T439515 Add trivy operator to staging - #224
Merged
Merged
Conversation
This structure is too many layers of indirection for my taste, but here we are at the minute.
Well if we're gonna use templates for such a basic thing, then we template that too...
I still think helm is overkill for this, and this kind of issue doesn't exactly make me think otherwise
dati18
requested changes
Sep 29, 2026
dati18
requested changes
Sep 29, 2026
Contributor
There was a problem hiding this comment.
Some more nitpicking:
- Change PR description to include
Bug: T439515at the end (git trailer purpose) - The PR title is a bit off. Suggestion: "Enable Trivy Operator in local and staging" (or Trivy Exporter)
- Not important, but on my side, VS Code omitted vague
unexpected scalarand similar errors. YAML validator doesn't understand Helm templates?
Because it's not depending on the other repo for values.yaml, having a single source removes confusion
Contributor
Author
|
I don't edit helm charts much at all these days, even rarer in vscode (I don't want the ai tooling that vscode pushes) so I don't know if there's a good yaml codeserver that handles helm templates or not. Other fixes implemented. |
dati18
requested changes
Sep 29, 2026
dati18
approved these changes
Sep 29, 2026
dati18
left a comment
Contributor
There was a problem hiding this comment.
I'm happy with the changes and the argo app in general. Approved!
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adding the trivy operator (includes the exporter) to staging.
I haven't added the values file pattern because that requires a PR to both repos (I don't like this level of indirection). I have tested the operator on the dev cluster I made.
I'm not yet sure how the prometheus metrics will be exposed, but this enables
kubectl get vulnerabilityreports -o wide -Ato show the reports, and piping that tojq '.items[] | .metadata.namespace+","+.metadata.labels["trivy-operator.container.name"]+","+(.report.summary.criticalCount|tostring)' -rwill give a list of criticals per object per namespace. Piping that toawk -F',' '{sum+=$3;print}END{print sum " critical vulnerabilities on the cluster"}'will give a count of all vulns on the cluster.Bug: T439515