Rancher Manager
:::info Coming soon This section will be written when this component is deployed. :::
Rancher Manager runs on the RKE2 management cluster and provides the unified control plane for the enclave — cluster lifecycle, RBAC, policy, and the Carbide CSR + Stigatron compliance layer.
What it provides
- Multi-cluster management UI at
rancher.carbide-enclave.kubernerdes.com(VIP.30) - OIDC authentication via Keycloak
- Carbide CSR — cryptographically-verified image provenance for all enclave workloads
- Stigatron — STIG compliance reporting and remediation tracking
system-default-registrypointing at Harbor (all chart-deployed images pull from Harbor)
Prerequisites
- Keycloak running — Keycloak
- Harbor registry populated via Hauler push — Harbor
- Carbide registry credentials in
~/.config/RGS/creds