From d20ac27851fc505a3a7dc5e56bbeec4c53e56b4a Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 10:48:47 +0200 Subject: [PATCH 1/7] Adding the trivy operator to the helm chart. This structure is too many layers of indirection for my taste, but here we are at the minute. --- .../argocd-apps/templates/trivy-operator.yaml | 28 +++++++++++++++++++ charts/argocd-apps/values.yaml | 1 + 2 files changed, 29 insertions(+) create mode 100644 charts/argocd-apps/templates/trivy-operator.yaml diff --git a/charts/argocd-apps/templates/trivy-operator.yaml b/charts/argocd-apps/templates/trivy-operator.yaml new file mode 100644 index 0000000..7ddaf11 --- /dev/null +++ b/charts/argocd-apps/templates/trivy-operator.yaml @@ -0,0 +1,28 @@ +apiVersion: argoproj.io/v1alpha1 +kind: Application +metadata: + name: trivy-exporter + namespace: argocd +spec: + destination: + namespace: trivy-system + server: {{ .Values.clusterUrl }} + project: {{ .Values.environment }} + sources: + - repoURL: oci://ghcr.io/aquasecurity/helm-charts/trivy-operator + targetRevision: {{ .Values.chartVersions.trivy-exporter }} + chart: trivy-exporter + helm: + valuesObject: + operator: + namespace: trivy-system + scanJobTimeout: 60m + - repoURL: {{ .Values.repoUrls.deploy }} + targetRevision: HEAD + ref: deployRepo + + syncPolicy: + automated: + # disable self-healing for local env so we can use skaffold + selfHeal: {{- if eq .Values.environment "local" }} false {{ else }} true {{ end }} + prune: false \ No newline at end of file diff --git a/charts/argocd-apps/values.yaml b/charts/argocd-apps/values.yaml index 9a763ab..9573d44 100644 --- a/charts/argocd-apps/values.yaml +++ b/charts/argocd-apps/values.yaml @@ -7,4 +7,5 @@ environment: production chartVersions: wbaasUi: 0.4.0 wbaasApi: 0.32.1 + trivy-exporter: 0.32.1 # "inherits" values from argocd-config chart From 60b2e2ea8f06c5b0610763d6f543c049e312e34e Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 10:57:34 +0200 Subject: [PATCH 2/7] Specifically staging --- charts/argocd-apps/templates/trivy-operator.yaml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/charts/argocd-apps/templates/trivy-operator.yaml b/charts/argocd-apps/templates/trivy-operator.yaml index 7ddaf11..0792753 100644 --- a/charts/argocd-apps/templates/trivy-operator.yaml +++ b/charts/argocd-apps/templates/trivy-operator.yaml @@ -1,3 +1,4 @@ +{{ if eq .Values.environment "staging" -}} apiVersion: argoproj.io/v1alpha1 kind: Application metadata: @@ -25,4 +26,5 @@ spec: automated: # disable self-healing for local env so we can use skaffold selfHeal: {{- if eq .Values.environment "local" }} false {{ else }} true {{ end }} - prune: false \ No newline at end of file + prune: false +{{- end }} \ No newline at end of file From c27c76658ca382d0992b690340193180d5e49973 Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 10:58:06 +0200 Subject: [PATCH 3/7] Allow trivy operator Well if we're gonna use templates for such a basic thing, then we template that too... --- charts/argocd-config/templates/projects.yaml | 1 + charts/argocd-config/values.yaml | 2 ++ 2 files changed, 3 insertions(+) diff --git a/charts/argocd-config/templates/projects.yaml b/charts/argocd-config/templates/projects.yaml index c8368d7..c5f60e8 100644 --- a/charts/argocd-config/templates/projects.yaml +++ b/charts/argocd-config/templates/projects.yaml @@ -17,6 +17,7 @@ spec: sourceRepos: - {{ .Values.repoUrls.deploy }} - {{ .Values.repoUrls.wbstack }} + {{- .Values.repoUrls.other | toYaml | nindent 2 }} clusterResourceWhitelist: - group: rbac.authorization.k8s.io kind: ClusterRole diff --git a/charts/argocd-config/values.yaml b/charts/argocd-config/values.yaml index c6bd153..1a30586 100644 --- a/charts/argocd-config/values.yaml +++ b/charts/argocd-config/values.yaml @@ -5,3 +5,5 @@ appOfAppsVersion: 2.1.0 repoUrls: deploy: https://github.com/wmde/wbaas-deploy wbstack: https://wbstack.github.io/charts + other: + - oci://ghcr.io/aquasecurity/helm-charts/trivy-operator From 8e05ee2c8f30e1b3b8144389201959a6e533720f Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 12:22:57 +0200 Subject: [PATCH 4/7] Bumping the version --- charts/argocd-apps/Chart.yaml | 2 +- charts/argocd-config/Chart.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/argocd-apps/Chart.yaml b/charts/argocd-apps/Chart.yaml index a8df58a..e311359 100644 --- a/charts/argocd-apps/Chart.yaml +++ b/charts/argocd-apps/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: argocd-apps description: Chart to deploy WBaaS apps in an "app-of-apps" pattern via ArgoCD type: application -version: 2.1.0 +version: 2.2.0 appVersion: "1.0" maintainers: - name: WBstack diff --git a/charts/argocd-config/Chart.yaml b/charts/argocd-config/Chart.yaml index 92a56cb..4a9e356 100644 --- a/charts/argocd-config/Chart.yaml +++ b/charts/argocd-config/Chart.yaml @@ -2,7 +2,7 @@ apiVersion: v2 name: argocd-config description: Chart to deploy ArgoCD configuration (including the argocd-apps chart) type: application -version: 2.1.2 +version: 2.1.3 appVersion: "1.0" maintainers: - name: WBstack From d884d8ff2f082a2f9fa76ee2c24bc5be196d9c31 Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 12:25:44 +0200 Subject: [PATCH 5/7] Helm is picky with variable names I still think helm is overkill for this, and this kind of issue doesn't exactly make me think otherwise --- charts/argocd-apps/templates/trivy-operator.yaml | 2 +- charts/argocd-apps/values.yaml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/charts/argocd-apps/templates/trivy-operator.yaml b/charts/argocd-apps/templates/trivy-operator.yaml index 0792753..4007546 100644 --- a/charts/argocd-apps/templates/trivy-operator.yaml +++ b/charts/argocd-apps/templates/trivy-operator.yaml @@ -11,7 +11,7 @@ spec: project: {{ .Values.environment }} sources: - repoURL: oci://ghcr.io/aquasecurity/helm-charts/trivy-operator - targetRevision: {{ .Values.chartVersions.trivy-exporter }} + targetRevision: {{ .Values.chartVersions.trivyOperator }} chart: trivy-exporter helm: valuesObject: diff --git a/charts/argocd-apps/values.yaml b/charts/argocd-apps/values.yaml index 9573d44..35133e7 100644 --- a/charts/argocd-apps/values.yaml +++ b/charts/argocd-apps/values.yaml @@ -7,5 +7,5 @@ environment: production chartVersions: wbaasUi: 0.4.0 wbaasApi: 0.32.1 - trivy-exporter: 0.32.1 + trivyOperator: 0.32.1 # "inherits" values from argocd-config chart From 078d96605b050742277629b36cee73e670a46be1 Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 15:52:26 +0200 Subject: [PATCH 6/7] Switching to single-source chart Because it's not depending on the other repo for values.yaml, having a single source removes confusion --- .../argocd-apps/templates/trivy-operator.yaml | 22 ++++++++----------- 1 file changed, 9 insertions(+), 13 deletions(-) diff --git a/charts/argocd-apps/templates/trivy-operator.yaml b/charts/argocd-apps/templates/trivy-operator.yaml index 4007546..c4f8b8e 100644 --- a/charts/argocd-apps/templates/trivy-operator.yaml +++ b/charts/argocd-apps/templates/trivy-operator.yaml @@ -9,19 +9,15 @@ spec: namespace: trivy-system server: {{ .Values.clusterUrl }} project: {{ .Values.environment }} - sources: - - repoURL: oci://ghcr.io/aquasecurity/helm-charts/trivy-operator - targetRevision: {{ .Values.chartVersions.trivyOperator }} - chart: trivy-exporter - helm: - valuesObject: - operator: - namespace: trivy-system - scanJobTimeout: 60m - - repoURL: {{ .Values.repoUrls.deploy }} - targetRevision: HEAD - ref: deployRepo - + source: + repoURL: oci://ghcr.io/aquasecurity/helm-charts/trivy-operator + targetRevision: {{ .Values.chartVersions.trivyOperator }} + chart: trivy-operator + helm: + valuesObject: + operator: + namespace: trivy-system + scanJobTimeout: 60m syncPolicy: automated: # disable self-healing for local env so we can use skaffold From ffd3bc762d21fc06a2f4e8710fddbeab57d0ec8f Mon Sep 17 00:00:00 2001 From: Martyn Ranyard Date: Tue, 29 Sep 2026 17:41:59 +0200 Subject: [PATCH 7/7] leftover from context switching --- charts/argocd-apps/templates/trivy-operator.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/charts/argocd-apps/templates/trivy-operator.yaml b/charts/argocd-apps/templates/trivy-operator.yaml index c4f8b8e..9745839 100644 --- a/charts/argocd-apps/templates/trivy-operator.yaml +++ b/charts/argocd-apps/templates/trivy-operator.yaml @@ -2,7 +2,7 @@ apiVersion: argoproj.io/v1alpha1 kind: Application metadata: - name: trivy-exporter + name: trivy-operator namespace: argocd spec: destination: