Skip to content

T439515 Add trivy operator to staging - #224

Merged
ranyardm-wmde merged 7 commits into
mainfrom
T439515-trivy-exporter-staging
Sep 29, 2026
Merged

ranyardm-wmde merged 7 commits into
mainfrom
T439515-trivy-exporter-staging

Conversation

@ranyardm-wmde

@ranyardm-wmde ranyardm-wmde commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Adding the trivy operator (includes the exporter) to staging.

I haven't added the values file pattern because that requires a PR to both repos (I don't like this level of indirection). I have tested the operator on the dev cluster I made.

I'm not yet sure how the prometheus metrics will be exposed, but this enables kubectl get vulnerabilityreports -o wide -A to show the reports, and piping that to jq '.items[] | .metadata.namespace+","+.metadata.labels["trivy-operator.container.name"]+","+(.report.summary.criticalCount|tostring)' -r will give a list of criticals per object per namespace. Piping that to awk -F',' '{sum+=$3;print}END{print sum " critical vulnerabilities on the cluster"}' will give a count of all vulns on the cluster.

Bug: T439515

This structure is too many layers of indirection for my taste, but here
we are at the minute.
Well if we're gonna use templates for such a basic thing, then we
template that too...
I still think helm is overkill for this, and this kind of issue doesn't
exactly make me think otherwise
Comment thread charts/argocd-apps/templates/trivy-operator.yaml Outdated
Comment thread charts/argocd-apps/templates/trivy-operator.yaml Outdated
Comment thread charts/argocd-apps/templates/trivy-operator.yaml

@dati18 dati18 left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Some more nitpicking:

  • Change PR description to include Bug: T439515 at the end (git trailer purpose)
  • The PR title is a bit off. Suggestion: "Enable Trivy Operator in local and staging" (or Trivy Exporter)
  • Not important, but on my side, VS Code omitted vague unexpected scalar and similar errors. YAML validator doesn't understand Helm templates?

@ranyardm-wmde ranyardm-wmde changed the title T439515 trivy exporter staging T439515 Add trivy operator to staging Sep 29, 2026
Because it's not depending on the other repo for values.yaml, having a
single source removes confusion
@ranyardm-wmde

Copy link
Copy Markdown
Contributor Author

I don't edit helm charts much at all these days, even rarer in vscode (I don't want the ai tooling that vscode pushes) so I don't know if there's a good yaml codeserver that handles helm templates or not.

Other fixes implemented.

Comment thread charts/argocd-apps/templates/trivy-operator.yaml Outdated

@dati18 dati18 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm happy with the changes and the argo app in general. Approved!

@ranyardm-wmde
ranyardm-wmde added this pull request to the merge queue Sep 29, 2026
Merged via the queue into main with commit 2f296ed Sep 29, 2026
2 checks passed
@ranyardm-wmde
ranyardm-wmde deleted the T439515-trivy-exporter-staging branch September 29, 2026 15:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants