diff --git a/docs/index.md b/docs/index.md index 362ee21968..f0d740fd0a 100644 --- a/docs/index.md +++ b/docs/index.md @@ -324,6 +324,8 @@ For non in-cluster execution, you can provide the location of the KubeConfig fil ```console prowler kubernetes --kubeconfig-file path ``` +???+ note + If no `--kubeconfig-file` is provided, Prowler will use the default KubeConfig file location (`~/.kube/config`). For in-cluster execution, you can use the supplied yaml to run Prowler as a job within a new Prowler namespace: ```console diff --git a/prowler/providers/kubernetes/kubernetes_provider.py b/prowler/providers/kubernetes/kubernetes_provider.py index b00a6c1e01..c00ba3fadf 100644 --- a/prowler/providers/kubernetes/kubernetes_provider.py +++ b/prowler/providers/kubernetes/kubernetes_provider.py @@ -3,6 +3,7 @@ import sys from argparse import Namespace from colorama import Fore, Style +from kubernetes.config.config_exception import ConfigException from kubernetes import client, config from prowler.config.config import load_and_validate_config_file @@ -124,19 +125,18 @@ class KubernetesProvider(Provider): Tuple: A tuple containing the API client and the context. """ try: - if kubeconfig_file: - logger.info(f"Using kubeconfig file: {kubeconfig_file}") + logger.info(f"Using kubeconfig file: {kubeconfig_file}") + try: config.load_kube_config( - config_file=os.path.abspath(kubeconfig_file), context=input_context + config_file=( + os.path.abspath(kubeconfig_file) + if kubeconfig_file != "~/.kube/config" + else os.path.expanduser(kubeconfig_file) + ), + context=input_context, ) - if input_context: - contexts = config.list_kube_config_contexts()[0] - for context_item in contexts: - if context_item["name"] == input_context: - context = context_item - else: - context = config.list_kube_config_contexts()[1] - else: + except ConfigException: + # If the kubeconfig file is not found, try to use the in-cluster config logger.info("Using in-cluster config") config.load_incluster_config() context = { @@ -146,6 +146,14 @@ class KubernetesProvider(Provider): "user": "service-account-name", # Also a placeholder }, } + else: + if input_context: + contexts = config.list_kube_config_contexts()[0] + for context_item in contexts: + if context_item["name"] == input_context: + context = context_item + else: + context = config.list_kube_config_contexts()[1] return KubernetesSession(api_client=client.ApiClient(), context=context) except Exception as error: logger.critical( diff --git a/prowler/providers/kubernetes/lib/arguments/arguments.py b/prowler/providers/kubernetes/lib/arguments/arguments.py index 27be298baa..c6aeace363 100644 --- a/prowler/providers/kubernetes/lib/arguments/arguments.py +++ b/prowler/providers/kubernetes/lib/arguments/arguments.py @@ -12,6 +12,7 @@ def init_parser(self): nargs="?", metavar="FILE_PATH", help="Path to the kubeconfig file to use for CLI requests. Not necessary for in-cluster execution.", + default="~/.kube/config", ) k8s_auth_subparser.add_argument( "--context", diff --git a/tests/lib/cli/parser_test.py b/tests/lib/cli/parser_test.py index c0e2d2ee15..e6bf1dc2b2 100644 --- a/tests/lib/cli/parser_test.py +++ b/tests/lib/cli/parser_test.py @@ -189,7 +189,7 @@ class Test_Parser: assert not parsed.list_compliance assert not parsed.list_compliance_requirements assert not parsed.list_categories - assert not parsed.kubeconfig_file + assert parsed.kubeconfig_file == "~/.kube/config" assert not parsed.context assert not parsed.namespace