Skip to content

Commit 7d6a33a

Browse files
committed
Merge branch '2022.4' into updateKbRegistry
2 parents 5937119 + dadc6c2 commit 7d6a33a

File tree

6 files changed

+41
-20
lines changed

6 files changed

+41
-20
lines changed

enforcers/kube_enforcer/kubernetes_and_openshift/manifests/kube_enforcer_advanced_trivy/001_kube_enforcer_config.yaml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1096,7 +1096,7 @@ metadata:
10961096
labels:
10971097
app.kubernetes.io/name: trivy-operator
10981098
app.kubernetes.io/instance: trivy-operator
1099-
app.kubernetes.io/version: "0.16.1"
1099+
app.kubernetes.io/version: "0.20.1"
11001100
app.kubernetes.io/managed-by: kubectl
11011101
data:
11021102
trivy.repository: "ghcr.io/aquasecurity/trivy"
@@ -1124,7 +1124,7 @@ metadata:
11241124
labels:
11251125
app.kubernetes.io/name: trivy-operator
11261126
app.kubernetes.io/instance: trivy-operator
1127-
app.kubernetes.io/version: "0.16.1"
1127+
app.kubernetes.io/version: "0.20.1"
11281128
app.kubernetes.io/managed-by: kubectl
11291129
data:
11301130
scanJob.podTemplateContainerSecurityContext: "{\"allowPrivilegeEscalation\":false,\"capabilities\":{\"drop\":[\"ALL\"]},\"privileged\":false,\"readOnlyRootFilesystem\":true}"
@@ -1141,7 +1141,7 @@ metadata:
11411141
labels:
11421142
app.kubernetes.io/name: trivy-operator
11431143
app.kubernetes.io/instance: trivy-operator
1144-
app.kubernetes.io/version: "0.16.1"
1144+
app.kubernetes.io/version: "0.20.1"
11451145
app.kubernetes.io/managed-by: kubectl
11461146
data:
11471147
---
@@ -1153,7 +1153,7 @@ metadata:
11531153
labels:
11541154
app.kubernetes.io/name: trivy-operator
11551155
app.kubernetes.io/instance: trivy-operator
1156-
app.kubernetes.io/version: "0.16.1"
1156+
app.kubernetes.io/version: "0.20.1"
11571157
app.kubernetes.io/managed-by: kubectl
11581158
---
11591159
apiVersion: v1
@@ -1164,7 +1164,7 @@ metadata:
11641164
labels:
11651165
app.kubernetes.io/name: trivy-operator
11661166
app.kubernetes.io/instance: trivy-operator
1167-
app.kubernetes.io/version: "0.16.1"
1167+
app.kubernetes.io/version: "0.20.1"
11681168
app.kubernetes.io/managed-by: kubectl
11691169
---
11701170
apiVersion: rbac.authorization.k8s.io/v1
@@ -1402,7 +1402,7 @@ metadata:
14021402
labels:
14031403
app.kubernetes.io/name: trivy-operator
14041404
app.kubernetes.io/instance: trivy-operator
1405-
app.kubernetes.io/version: "0.16.1"
1405+
app.kubernetes.io/version: "0.20.1"
14061406
app.kubernetes.io/managed-by: kubectl
14071407
roleRef:
14081408
apiGroup: rbac.authorization.k8s.io
@@ -1421,7 +1421,7 @@ metadata:
14211421
labels:
14221422
app.kubernetes.io/name: trivy-operator
14231423
app.kubernetes.io/instance: trivy-operator
1424-
app.kubernetes.io/version: "0.16.1"
1424+
app.kubernetes.io/version: "0.20.1"
14251425
app.kubernetes.io/managed-by: kubectl
14261426
rules:
14271427
- apiGroups:
@@ -1451,7 +1451,7 @@ metadata:
14511451
labels:
14521452
app.kubernetes.io/name: trivy-operator
14531453
app.kubernetes.io/instance: trivy-operator
1454-
app.kubernetes.io/version: "0.16.1"
1454+
app.kubernetes.io/version: "0.20.1"
14551455
app.kubernetes.io/managed-by: kubectl
14561456
roleRef:
14571457
apiGroup: rbac.authorization.k8s.io

enforcers/kube_enforcer/kubernetes_and_openshift/manifests/kube_enforcer_advanced_trivy/003_kube_enforcer_deploy.yaml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,7 @@ metadata:
158158
labels:
159159
app.kubernetes.io/name: trivy-operator
160160
app.kubernetes.io/instance: trivy-operator
161-
app.kubernetes.io/version: "0.16.1"
161+
app.kubernetes.io/version: "0.20.1"
162162
app.kubernetes.io/managed-by: kubectl
163163
spec:
164164
replicas: 1
@@ -178,7 +178,7 @@ spec:
178178
automountServiceAccountToken: true
179179
containers:
180180
- name: "trivy-operator"
181-
image: "docker.io/aquasec/trivy-operator:0.16.1"
181+
image: "docker.io/aquasec/trivy-operator:0.20.1"
182182
imagePullPolicy: IfNotPresent
183183
env:
184184
- name: OPERATOR_NAMESPACE
@@ -245,6 +245,8 @@ spec:
245245
value: "10h"
246246
- name: OPERATOR_MERGE_RBAC_FINDING_WITH_CONFIG_AUDIT
247247
value: "true"
248+
- name: CONTROLLER_CACHE_SYNC_TIMEOUT
249+
value: "5m"
248250
ports:
249251
- name: metrics
250252
containerPort: 8080

enforcers/kube_enforcer/kubernetes_and_openshift/manifests/kube_enforcer_trivy/001_kube_enforcer_config.yaml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -946,7 +946,7 @@ metadata:
946946
labels:
947947
app.kubernetes.io/name: trivy-operator
948948
app.kubernetes.io/instance: trivy-operator
949-
app.kubernetes.io/version: "0.16.1"
949+
app.kubernetes.io/version: "0.20.1"
950950
app.kubernetes.io/managed-by: kubectl
951951
data:
952952
trivy.repository: "ghcr.io/aquasecurity/trivy"
@@ -974,7 +974,7 @@ metadata:
974974
labels:
975975
app.kubernetes.io/name: trivy-operator
976976
app.kubernetes.io/instance: trivy-operator
977-
app.kubernetes.io/version: "0.16.1"
977+
app.kubernetes.io/version: "0.20.1"
978978
app.kubernetes.io/managed-by: kubectl
979979
data:
980980
scanJob.podTemplateContainerSecurityContext: "{\"allowPrivilegeEscalation\":false,\"capabilities\":{\"drop\":[\"ALL\"]},\"privileged\":false,\"readOnlyRootFilesystem\":true}"
@@ -991,7 +991,7 @@ metadata:
991991
labels:
992992
app.kubernetes.io/name: trivy-operator
993993
app.kubernetes.io/instance: trivy-operator
994-
app.kubernetes.io/version: "0.16.1"
994+
app.kubernetes.io/version: "0.20.1"
995995
app.kubernetes.io/managed-by: kubectl
996996
data:
997997
---
@@ -1003,7 +1003,7 @@ metadata:
10031003
labels:
10041004
app.kubernetes.io/name: trivy-operator
10051005
app.kubernetes.io/instance: trivy-operator
1006-
app.kubernetes.io/version: "0.16.1"
1006+
app.kubernetes.io/version: "0.20.1"
10071007
app.kubernetes.io/managed-by: kubectl
10081008
---
10091009
apiVersion: v1
@@ -1014,7 +1014,7 @@ metadata:
10141014
labels:
10151015
app.kubernetes.io/name: trivy-operator
10161016
app.kubernetes.io/instance: trivy-operator
1017-
app.kubernetes.io/version: "0.16.1"
1017+
app.kubernetes.io/version: "0.20.1"
10181018
app.kubernetes.io/managed-by: kubectl
10191019
---
10201020
apiVersion: rbac.authorization.k8s.io/v1
@@ -1252,7 +1252,7 @@ metadata:
12521252
labels:
12531253
app.kubernetes.io/name: trivy-operator
12541254
app.kubernetes.io/instance: trivy-operator
1255-
app.kubernetes.io/version: "0.16.1"
1255+
app.kubernetes.io/version: "0.20.1"
12561256
app.kubernetes.io/managed-by: kubectl
12571257
roleRef:
12581258
apiGroup: rbac.authorization.k8s.io
@@ -1271,7 +1271,7 @@ metadata:
12711271
labels:
12721272
app.kubernetes.io/name: trivy-operator
12731273
app.kubernetes.io/instance: trivy-operator
1274-
app.kubernetes.io/version: "0.16.1"
1274+
app.kubernetes.io/version: "0.20.1"
12751275
app.kubernetes.io/managed-by: kubectl
12761276
rules:
12771277
- apiGroups:
@@ -1301,7 +1301,7 @@ metadata:
13011301
labels:
13021302
app.kubernetes.io/name: trivy-operator
13031303
app.kubernetes.io/instance: trivy-operator
1304-
app.kubernetes.io/version: "0.16.1"
1304+
app.kubernetes.io/version: "0.20.1"
13051305
app.kubernetes.io/managed-by: kubectl
13061306
roleRef:
13071307
apiGroup: rbac.authorization.k8s.io

enforcers/kube_enforcer/kubernetes_and_openshift/manifests/kube_enforcer_trivy/003_kube_enforcer_deploy.yaml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -98,7 +98,7 @@ metadata:
9898
labels:
9999
app.kubernetes.io/name: trivy-operator
100100
app.kubernetes.io/instance: trivy-operator
101-
app.kubernetes.io/version: "0.16.1"
101+
app.kubernetes.io/version: "0.20.1"
102102
app.kubernetes.io/managed-by: kubectl
103103
spec:
104104
replicas: 1
@@ -118,7 +118,7 @@ spec:
118118
automountServiceAccountToken: true
119119
containers:
120120
- name: "trivy-operator"
121-
image: "docker.io/aquasec/trivy-operator:0.16.1"
121+
image: "docker.io/aquasec/trivy-operator:0.20.1"
122122
imagePullPolicy: IfNotPresent
123123
env:
124124
- name: OPERATOR_NAMESPACE
@@ -185,6 +185,8 @@ spec:
185185
value: "10h"
186186
- name: OPERATOR_MERGE_RBAC_FINDING_WITH_CONFIG_AUDIT
187187
value: "true"
188+
- name: CONTROLLER_CACHE_SYNC_TIMEOUT
189+
value: "5m"
188190
ports:
189191
- name: metrics
190192
containerPort: 8080

scanner/kubernetes_and_openshift/manifests/003_scanner_configmap.yaml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,3 +18,10 @@ data:
1818

1919
# Set this to 1 to establish mTLS connection with CyberCenter
2020
#OFFLINE_CC_MTLS_ENABLE: "1"
21+
22+
#health monitor is supported from SaaS scanner version 2407.4.20 and for on-prem 2022.4.613.7
23+
# enable below two values for health check monitor (liveness probe)
24+
#AQUA_HEALTH_MONITOR_ENABLED: "true"
25+
#AQUA_HEALTH_MONITOR_PORT: "8081"
26+
27+

scanner/kubernetes_and_openshift/manifests/004_scanner_deploy.yaml

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,16 @@ spec:
3636
- name: kube-scanner
3737
image: registry.aquasec.com/scanner:2022.4
3838
imagePullPolicy: Always
39+
# livenessProbe:
40+
# httpGet:
41+
# port: 8081
42+
# path: /healthz
43+
# scheme: HTTP
44+
# initialDelaySeconds: 15
45+
# periodSeconds: 60
46+
# successThreshold: 1
47+
# failureThreshold: 3
48+
# timeoutSeconds: 1
3949
# resources:
4050
# limits:
4151
# cpu: 2000m

0 commit comments

Comments
 (0)