<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR installation on GKE AutoPilot cluster in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235511#M8624</link>
    <description>&lt;P&gt;Cortex XDR seems to support GKE AutoPilot in latest release 8.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when generating the Kubernetes manifests on Cortex XDR dashboard, they will not deploy on AutoPilot cluster.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead, error message is given after kubectl apply command:&lt;BR /&gt;Violations details: {"[denied by autogke-default-linux-capabilities]":["linux capability 'SYS_ADMIN,SYSLOG,SYS_MODULE,SYS_RESOURCE,SYS_RAWIO,DAC_READ_SEARCH,NET_ADMIN,IPC_LOCK' on container 'cortex-agent' not allowed; Autopilot only allows the capabilities: 'AUDIT_WRITE,CHOWN,DAC_OVERRIDE,FOWNER,FSETID,KILL,MKNOD,NET_BIND_SERVICE,NET_RAW,SETFCAP,SETGID,SETPCAP,SETUID,SYS_CHROOT,SYS_PTRACE'."],"[denied by autogke-disallow-hostnamespaces]":["enabling hostPID is not allowed in Autopilot.","enabling hostIPC is not allowed in Autopilot.","enabling hostNetwork is not allowed in Autopilot."],"[denied by autogke-no-write-mode-hostpath]":["hostPath volume var-log in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume host-km-directory in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume agent-ids in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume host-fs used in container cortex-agent uses path / which is not allowed in Autopilot. Allowed path prefixes for hostPath volumes are: [/var/log/]."]}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please instruct how to configure AutoPilot or the manifest correctly. Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 06 Aug 2025 08:12:39 GMT</pubDate>
    <dc:creator>P.Timperi</dc:creator>
    <dc:date>2025-08-06T08:12:39Z</dc:date>
    <item>
      <title>Cortex XDR installation on GKE AutoPilot cluster</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235511#M8624</link>
      <description>&lt;P&gt;Cortex XDR seems to support GKE AutoPilot in latest release 8.9.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, when generating the Kubernetes manifests on Cortex XDR dashboard, they will not deploy on AutoPilot cluster.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Instead, error message is given after kubectl apply command:&lt;BR /&gt;Violations details: {"[denied by autogke-default-linux-capabilities]":["linux capability 'SYS_ADMIN,SYSLOG,SYS_MODULE,SYS_RESOURCE,SYS_RAWIO,DAC_READ_SEARCH,NET_ADMIN,IPC_LOCK' on container 'cortex-agent' not allowed; Autopilot only allows the capabilities: 'AUDIT_WRITE,CHOWN,DAC_OVERRIDE,FOWNER,FSETID,KILL,MKNOD,NET_BIND_SERVICE,NET_RAW,SETFCAP,SETGID,SETPCAP,SETUID,SYS_CHROOT,SYS_PTRACE'."],"[denied by autogke-disallow-hostnamespaces]":["enabling hostPID is not allowed in Autopilot.","enabling hostIPC is not allowed in Autopilot.","enabling hostNetwork is not allowed in Autopilot."],"[denied by autogke-no-write-mode-hostpath]":["hostPath volume var-log in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume host-km-directory in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume agent-ids in container cortex-agent is accessed in write mode; disallowed in Autopilot.","hostPath volume host-fs used in container cortex-agent uses path / which is not allowed in Autopilot. Allowed path prefixes for hostPath volumes are: [/var/log/]."]}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please instruct how to configure AutoPilot or the manifest correctly. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 08:12:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235511#M8624</guid>
      <dc:creator>P.Timperi</dc:creator>
      <dc:date>2025-08-06T08:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR installation on GKE AutoPilot cluster</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235529#M8627</link>
      <description>&lt;P&gt;Hello P.Timperi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please follow the step by step instructions on the document down below to install XDR on Kubernetes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the problem persists, please feel free to open a TAC support ticket:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.9/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-for-Kubernetes-Hosts" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/8.9/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-for-Kubernetes-Hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 12:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235529#M8627</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-08-06T12:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR installation on GKE AutoPilot cluster</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235614#M8634</link>
      <description>&lt;P&gt;Yes, I did follow the linked instructions and it works for standard GKE clusters, but not for AutoPilot.&lt;/P&gt;
&lt;P&gt;I found out that the partner agent needs to have AllowlistSynchronizer file path at Google:&lt;BR /&gt;&lt;A href="https://cloud.google.com/kubernetes-engine/docs/resources/autopilot-partners" target="_blank"&gt;https://cloud.google.com/kubernetes-engine/docs/resources/autopilot-partners&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://cloud.google.com/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads" target="_blank"&gt;https://cloud.google.com/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;But Cortex XDR is missing on the list of supported agents. I did try "&lt;SPAN&gt;Allowlist path:&amp;nbsp;&lt;/SPAN&gt;&lt;CODE dir="ltr" translate="no"&gt;Palo-Alto-Networks/prisma-cloud-defender/*&lt;/CODE&gt;", but it didn't work.. well, it is a different agent after all.&lt;BR /&gt;So, I guess the GKE AutoPilot support is not complete for Cortex XDR. It seems to miss the&amp;nbsp;AllowlistSynchronizer file path?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Aug 2025 12:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1235614#M8634</guid>
      <dc:creator>P.Timperi</dc:creator>
      <dc:date>2025-08-07T12:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR installation on GKE AutoPilot cluster</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1246875#M9063</link>
      <description>&lt;P&gt;Hey, please refer to our official documentation for this matter:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/9.1/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-for-Kubernetes-Hosts" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/9.1/Cortex-XDR-Agent-Administrator-Guide/Install-the-Cortex-XDR-Agent-for-Kubernetes-Hosts&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="bold"&gt;&lt;STRONG&gt;GKE Autopilot&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;running a privileged workload requires adding the path&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="code"&gt;(Palo-Alto-Networks/cortex-agent/*)&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to the corresponding allowlist file to an AllowlistSynchronizer custom resource. Then deploy the AllowlistSynchronizer to your cluster. For more details, visit&amp;nbsp;&lt;A href="https://cloud.google.com/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads#create-allowlistsynchronizer" target="_blank"&gt;https://cloud.google.com/kubernetes-engine/docs/how-to/run-autopilot-partner-workloads#create-allowlistsynchronizer&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Jan 2026 16:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-installation-on-gke-autopilot-cluster/m-p/1246875#M9063</guid>
      <dc:creator>atzarfaty</dc:creator>
      <dc:date>2026-01-28T16:36:33Z</dc:date>
    </item>
  </channel>
</rss>

