<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to pull image &amp;quot;registry-auth.twistlock.com/tw_&amp;lt;token&amp;gt;/twistlock/defender:defender_22_06_224&amp;quot; in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/574213#M1150</link>
    <description>&lt;P&gt;&lt;BR /&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207417"&gt;@Prisma&lt;/a&gt; Cloud Team,&lt;BR /&gt;&lt;BR /&gt;We are getting a similar error when deploying the twist-lock defender into a 1.23 EKS cluster&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_right_cap" data-stringify-type="code"&gt;ERRO 2024-01-22T18:15:48.310 defender.go:1623 No console connectivity&lt;/CODE&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;wss://us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;We have created a custom image using the defender image from the Prisma Cloud SaaS Console and added the required certificates and server parameters, we're able to deploy the defender in our test env in a minikube cluster (K8 version: 1.27) without any issues. We even have network connectivity from the cluster/nodes to&amp;nbsp;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&amp;nbsp; but when deploying it in the EKS cluster 1.23 we are getting the following error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_right_cap" data-stringify-type="code"&gt;ERRO 2024-01-22T18:15:48.310 defender.go:1623 No console connectivity&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;wss://us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jan 2024 05:14:24 GMT</pubDate>
    <dc:creator>PradeepGupta4</dc:creator>
    <dc:date>2024-01-24T05:14:24Z</dc:date>
    <item>
      <title>Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520729#M788</link>
      <description>&lt;P&gt;I'm getting the following error when deploying the twistlock defender into a 1.21 EKS cluster:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Failed to pull image "registry-auth.twistlock.com/tw_&amp;lt;token&amp;gt;/twistlock/defender:defender_22_06_224": rpc error: code = Unknown desc = Error response from daemon: Get "&lt;A href="https://registry-auth.twistlock.com/v2/" target="_blank"&gt;https://registry-auth.twistlock.com/v2/&lt;/A&gt;": x509: certificate signed by unknown authority&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Creating a custom AMI for EKS worker nodes is not an option, so I tried to work around the problem by downloading the container image from the console, loading it into docker locally, and publishing it to ECR. I'm able to deploy the defender at that point, but the container doesn't connect to the console using this method. The error in this case is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No console connectivity wss://us-east1.cloud.twistlock.com:443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone else encountered this? Any resolution? TIA&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 00:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520729#M788</guid>
      <dc:creator>benderj4</dc:creator>
      <dc:date>2022-11-09T00:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520733#M790</link>
      <description>&lt;P&gt;Hello Benderj4,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The x509 certificate error could be due to c&lt;SPAN&gt;ertificate path not being discovered by Prisma Cloud Compute.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The following Knowledge Article will help mitigate the error:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNgjCAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000oNgjCAE&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 00:50:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520733#M790</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-11-09T00:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520734#M791</link>
      <description>&lt;P&gt;The use case defined in your referenced article isn't consistent with mine. I'm not scanning any images. I'm trying to install the twistlock defender in the twistlock namespace.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm aware that I can add certificates to the truststore to get past this, but the EKS worker node images are locked down and I can't create a custom AMI to add certs. Are these images hosted anywhere that isn't using a self-signed cert? If not, let's focus on resolving the second error and I'll use my own twistlock container image.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 01:02:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520734#M791</guid>
      <dc:creator>benderj4</dc:creator>
      <dc:date>2022-11-09T01:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520738#M792</link>
      <description>&lt;P&gt;Regarding the second error, "&lt;SPAN&gt;No console connectivity wss://us-east1.cloud.twistlock.com:443", are you using self-hosted console or saas?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If self hosted, can you add the SAN under Names? Please refer to the screenshot.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: the SAN needs to match the option 3 of the deployment template for orchestrator defender.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 01:13:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520738#M792</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-11-09T01:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520739#M793</link>
      <description>&lt;P&gt;We're using the SaaS product.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 01:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520739#M793</guid>
      <dc:creator>benderj4</dc:creator>
      <dc:date>2022-11-09T01:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520740#M794</link>
      <description>&lt;P&gt;Hello Benderj4,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you run the following ping command from the place where you are deploying the defender to the console?&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;
&lt;P&gt;curl -sk -D - https://&amp;lt;CONSOLE_IP_ADDRESS&amp;gt;/api/v1/_ping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, please share output of the openssl command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Nov 2022 01:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520740#M794</guid>
      <dc:creator>USheikh</dc:creator>
      <dc:date>2022-11-09T01:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520947#M797</link>
      <description>&lt;P&gt;Hi BenderJ4,&lt;/P&gt;
&lt;P&gt;Prisma Cloud Compute does not support having any defender pre-installed on a host, commonly also referred to as a "golden image." The closest you could get would be automating deployment with other tools and scripts. On a similar note, we do not support hosting the single container defender in a private registry (although I've seen existing feature requests for this).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if the case is that you'd like to automate deployment of a daemonset and host the defender in a private registry, Prisma Cloud Compute does support that&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2022 22:41:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/520947#M797</guid>
      <dc:creator>CloudEngineer</dc:creator>
      <dc:date>2022-11-10T22:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to pull image "registry-auth.twistlock.com/tw_&lt;token&gt;/twistlock/defender:defender_22_06_224"</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/574213#M1150</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/207417"&gt;@Prisma&lt;/a&gt; Cloud Team,&lt;BR /&gt;&lt;BR /&gt;We are getting a similar error when deploying the twist-lock defender into a 1.23 EKS cluster&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_right_cap" data-stringify-type="code"&gt;ERRO 2024-01-22T18:15:48.310 defender.go:1623 No console connectivity&lt;/CODE&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;wss://us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;We have created a custom image using the defender image from the Prisma Cloud SaaS Console and added the required certificates and server parameters, we're able to deploy the defender in our test env in a minikube cluster (K8 version: 1.27) without any issues. We even have network connectivity from the cluster/nodes to&amp;nbsp;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&amp;nbsp; but when deploying it in the EKS cluster 1.23 we are getting the following error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_right_cap" data-stringify-type="code"&gt;ERRO 2024-01-22T18:15:48.310 defender.go:1623 No console connectivity&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;CODE class="c-mrkdwn__code c-mrkdwn__code--no_left_cap" data-stringify-type="code"&gt;&lt;A class="c-link c-link--focus-visible c-link--underline" href="wss://us-east1.cloud.twistlock.com/" target="_blank" rel="noopener noreferrer nofollow" data-stringify-link="wss://us-east1.cloud.twistlock.com:443" data-sk="tooltip_parent"&gt;wss://us-east1.cloud.twistlock.com:443&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 05:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/failed-to-pull-image-quot-registry-auth-twistlock-com-tw-lt/m-p/574213#M1150</guid>
      <dc:creator>PradeepGupta4</dc:creator>
      <dc:date>2024-01-24T05:14:24Z</dc:date>
    </item>
  </channel>
</rss>

