This topic helps you install Prisma Cloud in your Kubernetes cluster quickly. There are many ways to install Prisma Cloud, but use this workflow to quickly deploy Defenders and verify how information is accessible from the Prisma Cloud Console. After completing this procedure, you can modify the installation to match your needs.
To better understand clusters, read our cluster context topic.
To deploy Prisma Cloud Defenders, you use the command-line utility called , which is bundled with the Prisma Cloud software. The process has the following steps to give you full control over the created objects.
You can inspect, customize, and manage the YAML configuration files or Helm charts before deploying the Prisma Cloud Console and Defender. You can place the files or charts under source control to track changes, to integrate them with Continuos Integration and Continuos Development (CI/CD) pipelines, and to enable effective collaboration.
Each Prisma Cloud Defender is deployed as a DaemonSet to ensure that a Prisma Cloud Defender instance runs on each worker node of your cluster.
To deploy your Defenders smoothly, you must meet the following requirements.
- You have a valid Prisma Cloud license key and access token.
- You provisioned a Kubernetes cluster that meets the minimum system requirements and runs a supported Kubernetes version.
- You set up a Linux or macOS system to control your cluster, and you can access the cluster using the kubectl command-line utility.
- Your cluster uses any of the following runtimes. For more information about the runtimes that Prisma Cloud supports, see the system requirements.
- Docker Engine
- Install the Prisma Cloud command-line utility called twistcli, which is bundled with the Prisma Cloud software. You use twistcli to deploy the Defenders.
- You can create and delete namespaces in your cluster.
Required Firewall and Port Configuration
Open the following ports in your firewall.
Ports for the
Prisma Cloud Defenders:
- Incoming: None
- Outgoing: 443
Install the Prisma Cloud Command-Line Utility
To use Prisma Cloud as part of your Kubernetes deployment, you need the twistcli command-line utility and the Prisma Cloud Defenders.
- Ensure that your cluster configuration allows the Defenders to connect to the Prisma Cloud Console service. The Defenders connect to the Prisma Cloud Console service using a websocket over port 443 to retrieve policies and send data.
Install the Prisma Cloud Defender
This approach is called declarative object management. It allows you to work directly with the YAML configuration files. The benefit is that you get the full source code for the custom resources you create in your cluster, and you can use a version control tool to manage and track modifications. With YAML configuration files under version control, you can delete and reliably recreate DaemonSets in your environment.
If you don’t have kubectl access to your cluster, you can deploy Defender DaemonSets directly from the Console UI.
This procedure shows you how to deploy Defender DaemonSets using the twistcli command-line utility and declarative object management. You can also generate the installation commands using the Prisma Cloud Console UI under
Manage > Defenders > Deploy > Defenders. Installation scripts are provided for Linux and MacOS workstations. Use the twistcli command-line utility to generate the Defender DaemonSet YAML configuration files from Windows workstations. Deploy the custom resources with kubectl following this procedure.
- Get the PRISMA_CLOUD_COMPUTE_CONSOLE_URL value.
- Sign into Prisma Cloud.
- Go toCompute > Manage > System > Utilities.
- Copy the URL underPath to Console.
- Retrieve the hostname of the Prisma Cloud Console hostname to use as the value for PRISMA_CLOUD_COMPUTE_HOSTNAME.The hostname can be derived from the URL by removing the protocol scheme and path. It is simply the host part of the URL. You can also retrieve the hostname directly.
- Generate the DaemonSet custom resource for the Defender.
- Go toCompute > Manage > Defenders > Deploy > Defenders.
- SelectKubernetesfromStep 2: Choose the orchestrator type.
- Copy the hostname fromStep 3: The name that Defender will use to connect to this Console.
- Generate the defender.yaml file using the following twistcli command with the described parameters.$ <PLATFORM>/twistcli defender export kubernetes \ --user <ADMIN_USER> \ --address <PRISMA_CLOUD_COMPUTE_CONSOLE_URL> \ --cluster-address <PRISMA_CLOUD_COMPUTE_HOSTNAME> --cri
- <ADMIN_USER> is the name of a Prisma Cloud user with the System Admin role.
- <PRISMA_CLOUD_COMPUTE_CONSOLE_URL> specifies the address of the Prisma Cloud Compute Console.
- <PRISMA_CLOUD_COMPUTE_HOSTNAME> specifies the address Defender uses to connect to Prisma Cloud Console. You can use the external IP address exposed by your load balancer or the DNS name that you manually set up.
- For provider managed clusters, Prisma Cloud automatically gets the cluster name from your cloud provider.