1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["11513"],{62959:function(e,r,s){s.r(r),s.d(r,{frontMatter:()=>c,default:()=>h,toc:()=>o,metadata:()=>n,assets:()=>d,contentTitle:()=>l});var n=JSON.parse('{"id":"reference/resources/globalreport","title":"Global report","description":"API for this Calico Cloud resource.","source":"@site/calico-cloud_versioned_docs/version-21-2/reference/resources/globalreport.mdx","sourceDirName":"reference/resources","slug":"/reference/resources/globalreport","permalink":"/calico-cloud/reference/resources/globalreport","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico-cloud_versioned_docs/version-21-2/reference/resources/globalreport.mdx","tags":[],"version":"21-2","frontMatter":{"description":"API for this Calico Cloud resource."},"sidebar":"calicoCloudSidebar","previous":{"title":"Global network set","permalink":"/calico-cloud/reference/resources/globalnetworkset"},"next":{"title":"Global threat feed","permalink":"/calico-cloud/reference/resources/globalthreatfeed"}}'),t=s(72459),i=s(36870);let c={description:"API for this Calico Cloud resource."},l="Global report",d={},o=[{value:"Sample YAML",id:"sample-yaml",level:2},{value:"GlobalReport Definition",id:"globalreport-definition",level:2},{value:"Metadata",id:"metadata",level:3},{value:"Spec",id:"spec",level:3},{value:"EndpointsSelection",id:"endpointsselection",level:3},{value:"CISBenchmarkParams",id:"cisbenchmarkparams",level:3},{value:"CISBenchmarkFilter",id:"cisbenchmarkfilter",level:3},{value:"CISBenchmarkSelection",id:"cisbenchmarkselection",level:3},{value:"NamesAndLabelsMatch",id:"namesandlabelsmatch",level:3},{value:"Supported operations",id:"supported-operations",level:2}];function a(e){let r={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,i.a)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(r.header,{children:(0,t.jsx)(r.h1,{id:"global-report",children:"Global report"})}),"\n",(0,t.jsx)(r.p,{children:"A global report resource is a configuration for generating compliance reports. A global report configuration in Calico Cloud lets you:"}),"\n",(0,t.jsxs)(r.ul,{children:["\n",(0,t.jsx)(r.li,{children:"Specify report contents, frequency, and data filtering"}),"\n",(0,t.jsx)(r.li,{children:"Specify the node(s) on which to run the report generation jobs"}),"\n",(0,t.jsx)(r.li,{children:"Enable/disable creation of new jobs for generating the report"}),"\n"]}),"\n",(0,t.jsxs)(r.p,{children:["For ",(0,t.jsx)(r.code,{children:"kubectl"})," ",(0,t.jsx)(r.a,{href:"https://kubernetes.io/docs/reference/kubectl/overview/",children:"commands"}),", the following case-insensitive aliases\nmay be used to specify the resource type on the CLI:\n",(0,t.jsx)(r.code,{children:"globalreport.projectcalico.org"}),", ",(0,t.jsx)(r.code,{children:"globalreports.projectcalico.org"})," and abbreviations such as\n",(0,t.jsx)(r.code,{children:"globalreport.p"})," and ",(0,t.jsx)(r.code,{children:"globalreports.p"}),"."]}),"\n",(0,t.jsx)(r.h2,{id:"sample-yaml",children:"Sample YAML"}),"\n",(0,t.jsx)(r.pre,{children:(0,t.jsx)(r.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: GlobalReport\nmetadata:\n name: weekly-full-inventory\nspec:\n reportType: inventory\n schedule: 0 0 * * 0\n jobNodeSelector:\n nodetype: infrastructure\n\n---\napiVersion: projectcalico.org/v3\nkind: GlobalReport\nmetadata:\n name: hourly-accounts-networkaccess\nspec:\n reportType: network-access\n endpoints:\n namespaces:\n names: ['payable', 'collections', 'payroll']\n schedule: 0 * * * *\n\n---\napiVersion: projectcalico.org/v3\nkind: GlobalReport\nmetadata:\n name: monthly-widgets-controller-tigera-policy-audit\nspec:\n reportType: policy-audit\n schedule: 0 0 1 * *\n endpoints:\n serviceAccounts:\n names: ['controller']\n namespaces:\n names: ['widgets']\n\n---\napiVersion: projectcalico.org/v3\nkind: GlobalReport\nmetadata:\n name: daily-cis-benchmark\nspec:\n reportType: cis-benchmark\n schedule: 0 0 * * *\n cis:\n resultsFilters:\n - benchmarkSelection: { kubernetesVersion: '1.13' }\n exclude: ['1.1.4', '1.2.5']\n"})}),"\n",(0,t.jsx)(r.h2,{id:"globalreport-definition",children:"GlobalReport Definition"}),"\n",(0,t.jsx)(r.h3,{id:"metadata",children:"Metadata"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Field"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Accepted Values"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"name"}),(0,t.jsx)(r.td,{children:"The name of this report."}),(0,t.jsxs)(r.td,{children:["Lower-case alphanumeric with optional ",(0,t.jsx)(r.code,{children:"-"})," or ",(0,t.jsx)(r.code,{children:"."})]}),(0,t.jsx)(r.td,{children:"string"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"labels"}),(0,t.jsx)(r.td,{children:"A set of labels to apply to this report."}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:"map"})]})]})]}),"\n",(0,t.jsx)(r.h3,{id:"spec",children:"Spec"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Field"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Required"}),(0,t.jsx)(r.th,{children:"Accepted Values"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"reportType"}),(0,t.jsx)(r.td,{children:"The type of report to produce. This field controls the content of the report - see the links for each type for more details."}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsxs)(r.td,{children:[(0,t.jsx)(r.a,{href:"/calico-cloud/reference/resources/compliance-reports/cis-benchmark",children:"cis\u2011benchmark"}),", ",(0,t.jsx)(r.a,{href:"/calico-cloud/reference/resources/compliance-reports/inventory",children:"inventory"}),", ",(0,t.jsx)(r.a,{href:"/calico-cloud/reference/resources/compliance-reports/network-access",children:"network\u2011access"}),", ",(0,t.jsx)(r.a,{href:"/calico-cloud/reference/resources/compliance-reports/policy-audit",children:"policy\u2011audit"})]}),(0,t.jsx)(r.td,{children:"string"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"endpoints"}),(0,t.jsx)(r.td,{children:"Specify which endpoints are in scope. If omitted, selects everything."}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#endpointsselection",children:"EndpointsSelection"})})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"schedule"}),(0,t.jsxs)(r.td,{children:["Configure report frequency by specifying start and end time in ",(0,t.jsx)(r.a,{href:"https://en.wikipedia.org/wiki/Cron",children:"cron-format"}),". Reports are started 30 minutes (configurable) after the scheduled value to allow enough time for data archival. A maximum limit of 12 schedules per hour is enforced (an average of one report every 5 minutes)."]}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:"string"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"jobNodeSelector"}),(0,t.jsx)(r.td,{children:"Specify the node(s) for scheduling the report jobs using selectors."}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:"map"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"suspend"}),(0,t.jsx)(r.td,{children:"Disable future scheduled report jobs. In-flight reports are not affected."}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:"bool"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"cis"}),(0,t.jsx)(r.td,{children:"Parameters related to generating a CIS benchmark report."}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#cisbenchmarkparams",children:"CISBenchmarkParams"})})]})]})]}),"\n",(0,t.jsx)(r.h3,{id:"endpointsselection",children:"EndpointsSelection"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Field"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"selector"}),(0,t.jsx)(r.td,{children:"Endpoint label selector to restrict endpoint selection."}),(0,t.jsx)(r.td,{children:"string"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"namespaces"}),(0,t.jsx)(r.td,{children:"Namespace name and label selector to restrict endpoints by selected namespaces."}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#namesandlabelsmatch",children:"NamesAndLabelsMatch"})})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"serviceAccounts"}),(0,t.jsx)(r.td,{children:"Service account name and label selector to restrict endpoints by selected service accounts."}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#namesandlabelsmatch",children:"NamesAndLabelsMatch"})})]})]})]}),"\n",(0,t.jsx)(r.h3,{id:"cisbenchmarkparams",children:"CISBenchmarkParams"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Fields"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Required"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"highThreshold"}),(0,t.jsx)(r.td,{children:"Integer percentage value that determines the lower limit of passing tests to consider a node as healthy. Default: 100"}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:"int"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"medThreshold"}),(0,t.jsx)(r.td,{children:"Integer percentage value that determines the lower limit of passing tests to consider a node as unhealthy. Default: 50"}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:"int"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"includeUnscoredTests"}),(0,t.jsx)(r.td,{children:"Boolean value that when false, applies a filter to exclude tests that are marked as \u201CUnscored\u201D by the CIS benchmark standard. If true, the tests will be included in the report. Default: false"}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:"bool"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"numFailedTests"}),(0,t.jsx)(r.td,{children:"Integer value that sets the number of tests to display in the Top-failed Tests section of the CIS benchmark report. Default: 5"}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:"int"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"resultsFilters"}),(0,t.jsx)(r.td,{children:"Specifies an include or exclude filter to apply on the test results that will appear on the report."}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#cisbenchmarkfilter",children:"CISBenchmarkFilter"})})]})]})]}),"\n",(0,t.jsx)(r.h3,{id:"cisbenchmarkfilter",children:"CISBenchmarkFilter"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Fields"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Required"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"benchmarkSelection"}),(0,t.jsx)(r.td,{children:"Specify which set of benchmarks that this filter should apply to. Selects all benchmark types."}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:(0,t.jsx)(r.a,{href:"#cisbenchmarkselection",children:"CISBenchmarkSelection"})})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"exclude"}),(0,t.jsx)(r.td,{children:"Specify which benchmark tests to exclude"}),(0,t.jsx)(r.td,{children:"No"}
1),(0,t.jsx)(r.td,{children:"array of strings"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"include"}),(0,t.jsx)(r.td,{children:"Specify which benchmark tests to include only (higher precedence than exclude)"}),(0,t.jsx)(r.td,{children:"No"}),(0,t.jsx)(r.td,{children:"array of strings"})]})]})]}),"\n",(0,t.jsx)(r.h3,{id:"cisbenchmarkselection",children:"CISBenchmarkSelection"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Fields"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Required"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsx)(r.tbody,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"kubernetesVersion"}),(0,t.jsx)(r.td,{children:"Specifies a version of the benchmarks."}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsx)(r.td,{children:"string"})]})})]}),"\n",(0,t.jsx)(r.h3,{id:"namesandlabelsmatch",children:"NamesAndLabelsMatch"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Field"}),(0,t.jsx)(r.th,{children:"Description"}),(0,t.jsx)(r.th,{children:"Schema"})]})}),(0,t.jsxs)(r.tbody,{children:[(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"names"}),(0,t.jsx)(r.td,{children:"Set of resource names."}),(0,t.jsx)(r.td,{children:"list"})]}),(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"selector"}),(0,t.jsx)(r.td,{children:"Selects a set of resources by label."}),(0,t.jsx)(r.td,{children:"string"})]})]})]}),"\n",(0,t.jsxs)(r.p,{children:["Use the ",(0,t.jsx)(r.code,{children:"NamesAndLabelsMatch"}),"to limit the scope of endpoints. If both ",(0,t.jsx)(r.code,{children:"names"}),"\nand ",(0,t.jsx)(r.code,{children:"selector"})," are specified, the resource is identified using label ",(0,t.jsx)(r.em,{children:"AND"})," name\nmatch."]}),"\n",(0,t.jsx)(r.admonition,{type:"note",children:(0,t.jsxs)(r.p,{children:["To use the Calico Cloud compliance reporting feature, you must ensure all required resource types\nare being audited and the logs archived in Elasticsearch. You must explicitly configure the ",(0,t.jsx)(r.a,{href:"/calico-cloud/observability/kube-audit",children:"Kubernetes API Server"}),"\nto send audit logs for Kubernetes-owned resources\nto Elasticsearch."]})}),"\n",(0,t.jsx)(r.h2,{id:"supported-operations",children:"Supported operations"}),"\n",(0,t.jsxs)(r.table,{children:[(0,t.jsx)(r.thead,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.th,{children:"Datastore type"}),(0,t.jsx)(r.th,{children:"Create/Delete"}),(0,t.jsx)(r.th,{children:"Update"}),(0,t.jsx)(r.th,{children:"Get/List"}),(0,t.jsx)(r.th,{children:"Notes"})]})}),(0,t.jsx)(r.tbody,{children:(0,t.jsxs)(r.tr,{children:[(0,t.jsx)(r.td,{children:"Kubernetes API server"}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsx)(r.td,{children:"Yes"}),(0,t.jsx)(r.td,{})]})})]})]})}function h(e={}){let{wrapper:r}={...(0,i.a)(),...e.components};return r?(0,t.jsx)(r,{...e,children:(0,t.jsx)(a,{...e})}):a(e)}},36870:function(e,r,s){s.d(r,{Z:()=>l,a:()=>c});var n=s(84449);let t={},i=n.createContext(t);function c(e){let r=n.useContext(i);return n.useMemo(function(){return"function"==typeof e?e(r):{...r,...e}},[r,e])}function l(e){let r;return r=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:c(e.components),n.createElement(i.Provider,{value:r},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.