Configure the Kubernetes plugin to push the tags to the
specified device groups.
You must add a monitoring definition that includes the
name of the Kubernetes cluster from which Panorama retrieves predefined
labels and optionally a notify group.
A notify group
is required if the CN-Series is deployed in a namespace other than
kube-system.
A notify group is a list of device groups
that receive tag updates. For the Kubernetes plugin, the notify
group should include firewalls external to the cluster (meaning
that they do not belong to the same device group as the Kubernetes
cluster from which you are collecting attributes).
Because
you specify the device group name in the YAML files that are used to
deploy the CN-Series firewalls, the Kubernetes plugin automatically learns
of all device groups that are internal to the cluster and it automatically
pushes all predefined tags to those device groups by default.
The
Kubernetes plugin uses Kubernetes Secrets to dynamically learn
of the device groups within each cluster. Each time you deploy
a CN-MGMT StatefulSet, the Secret is published to the Kubernetes
API server and Panorama learns of it in the next monitoring interval.