{ "_v": 14, "composerId": "e934b96e-a11d-4ebc-8f59-1cb2ebc8cc34", "richText": "{\"root\":{\"children\":[{\"children\":[],\"format\":\"\",\"indent\":0,\"type\":\"paragraph\",\"version\":1}],\"format\":\"\",\"indent\":0,\"type\":\"root\",\"version\":1}}", "hasLoaded": true, "text": "", "fullConversationHeadersOnly": [ { "bubbleId": "2f4fbaa1-93ee-4533-8149-54c667ca32cc", "type": 1 }, { "bubbleId": "a27bdfe1-19ab-487d-8139-4d0777e99d7a", "type": 2 }, { "bubbleId": "fd570486-b204-449f-b2e9-0c34b46db5e8", "type": 2 }, { "bubbleId": "591af5bc-a116-4ca4-9490-616f8db4d97e", "type": 2 }, { "bubbleId": "d1091f13-8a61-4de5-874d-fe80a59cf8a3", "type": 2 }, { "bubbleId": "ebd127de-4d81-437f-b2b3-5f7eef3647eb", "type": 2 }, { "bubbleId": "03538778-6d16-4f92-a290-72aee765a505", "type": 2 }, { "bubbleId": "13375ca8-e202-4472-8e94-567f0f3811f4", "type": 2 }, { "bubbleId": "42ca5327-e930-4847-85f9-c7bda77111de", "type": 2 }, { "bubbleId": "849a512a-2683-4320-abc8-d29c83e3bda6", "type": 2 }, { "bubbleId": "815a1b26-bda0-405c-99ac-fb110f1db07b", "type": 2 }, { "bubbleId": "ddd023da-2757-4b20-b21c-9fc6757775e2", "type": 2 }, { "bubbleId": "8ca471de-029c-4837-8ccf-32d43520c397", "type": 2 }, { "bubbleId": "d8bf7d1f-fb28-4a0c-9d22-0074f661c165", "type": 2 }, { "bubbleId": "ec5e9688-bd86-4a25-b05d-5c434d2bf67d", "type": 2 }, { "bubbleId": "2055eee8-adc5-4565-8259-120a64af7be8", "type": 2 }, { "bubbleId": "8f25cdf4-c6fe-4bfb-b0ce-52a8b3e65617", "type": 2 }, { "bubbleId": "cd1f464d-cd5c-4be7-81f9-d39afe93108b", "type": 2 }, { "bubbleId": "e8b720d5-04fe-4ec9-8857-a16d1a7335b1", "type": 2 }, { "bubbleId": "87a0b240-56db-48aa-986c-51adb66c5605", "type": 2 }, { "bubbleId": "dd52376d-aac0-4555-9578-dd1bf7bc1aba", "type": 2 }, { "bubbleId": "be993d16-09db-4a34-a5ab-81ff00217fa4", "type": 2 }, { "bubbleId": "a6cc19e2-dee2-4236-9ae5-37b3b58b4543", "type": 2 }, { "bubbleId": "61be342f-5c8e-4cbb-99a1-f94dab05fbdc", "type": 2 }, { "bubbleId": "9aa5f30b-b19b-4850-a7f8-478e95730ab2", "type": 2 }, { "bubbleId": "b2c1c313-3dbd-439a-8294-16ffc9ef0a8c", "type": 2 }, { "bubbleId": "2456164a-2c96-4ddf-bee3-5e5ca06067c4", "type": 2 }, { "bubbleId": "a54ff4dd-91b6-4cd2-ae59-135a5b8db18c", "type": 2 }, { "bubbleId": "8bc37dd6-5481-4861-a603-96f90c322310", "type": 2 }, { "bubbleId": "6d8d2a6a-23a4-4c9f-ba7d-c769f2652563", "type": 2 }, { "bubbleId": "388e42be-4c17-43ce-8c59-7d3604036983", "type": 2 }, { "bubbleId": "5ca05fa4-69f7-4403-9b3d-e6d5d10e338a", "type": 2 }, { "bubbleId": "9c4ff888-cafd-474f-b868-2b4a40e97239", "type": 2 }, { "bubbleId": "40186727-0a86-486c-b8ee-3f76ae4639ff", "type": 2 }, { "bubbleId": "1b07eeba-5959-4eaf-9aa2-f0588e836ca5", "type": 2 }, { "bubbleId": "ac5f644c-7c4b-4ce8-82bd-98705e4419f1", "type": 2 }, { "bubbleId": "b17bc3db-5335-4ebb-85a9-c8e49a706e0f", "type": 2 }, { "bubbleId": "7b669f1a-abfa-4e0c-acc0-b9bb03bac940", "type": 2 }, { "bubbleId": "d44bffb7-4463-42bd-9464-da02834520f4", "type": 2 }, { "bubbleId": "c53de2c0-8ff1-4aa6-a88e-176ca85b8be1", "type": 1 }, { "bubbleId": "66cb38aa-ecc6-4726-8a60-0c7fd03e1ce1", "type": 2 }, { "bubbleId": "457ec122-a0f7-4cfe-902e-75abd2ec8566", "type": 2 }, { "bubbleId": "cbaa0e0f-415f-437e-bc74-1cc1c49b6870", "type": 2 }, { "bubbleId": "5a7d9ba9-0611-41ae-be10-158681a30fd6", "type": 2 }, { "bubbleId": "39e4e1dc-3f6c-4069-a3c6-06e03e776048", "type": 2 }, { "bubbleId": "2f7843a9-d02e-4acb-856c-572a94e81137", "type": 2 }, { "bubbleId": "59e7530c-71b0-4d2a-98b2-e1f3f5c2308b", "type": 2 }, { "bubbleId": "167db4db-4cce-4781-9abc-51fe15cfbf7d", "type": 2 }, { "bubbleId": "ad925f07-4090-4dfc-ae56-dd5d49e2e758", "type": 2 }, { "bubbleId": "8d9f9ed4-4976-4efc-b7d0-33eac249ee10", "type": 2 }, { "bubbleId": "f568ab44-6993-4789-95f5-b16740d886d4", "type": 2 }, { "bubbleId": "47f2cf17-bc04-4f37-a2df-66d9a7e190b1", "type": 2 }, { "bubbleId": "68034c2d-f9f4-42c5-aaff-904c3815c4d0", "type": 2 }, { "bubbleId": "cc2cd0f0-b8db-4b73-8bda-a4047d724ade", "type": 2 }, { "bubbleId": "dc592989-5337-4e7f-a9ae-202212c3229c", "type": 2 }, { "bubbleId": "15aa8719-45d9-4add-9676-8994a7642fce", "type": 2 }, { "bubbleId": "69fc6973-2f75-4334-a5e0-d72787143a3c", "type": 2 }, { "bubbleId": "d53b77de-f74b-422a-b596-5cd468fd1f04", "type": 2 }, { "bubbleId": "24879b24-ecfa-463b-ad54-62e902bf486b", "type": 2 }, { "bubbleId": "643d5cf4-521d-4ffa-9d4a-947c1159aa6d", "type": 2 }, { "bubbleId": "f23b1a69-1cda-46f6-895e-05f26b7661c3", "type": 2 }, { "bubbleId": "271057e1-25d8-46a4-9200-4251b23a42e5", "type": 2 }, { "bubbleId": "05586fe9-93ba-4daa-9f96-fd96e68ade8d", "type": 2 }, { "bubbleId": "6e6ca964-abc4-4c66-a510-a4c4734e295e", "type": 2 }, { "bubbleId": "23254172-81fb-45fb-a686-7871555d8cbb", "type": 2 }, { "bubbleId": "7b68bca8-e6b8-4e1a-a189-55a2e08e476f", "type": 2 }, { "bubbleId": "b7d626fe-e9e6-4bbc-963e-dbde9de96a3e", "type": 2 }, { "bubbleId": "a4e781c8-82b7-4fdb-af81-9dbcb553f1b5", "type": 2 }, { "bubbleId": "59602b00-0108-4045-af33-c8caca42a4e3", "type": 2 }, { "bubbleId": "c8dc48f3-633a-40d0-a914-a39bc1ae091f", "type": 2 }, { "bubbleId": "a20b9465-4d26-4dc8-8405-302df05d9383", "type": 2 }, { "bubbleId": "421ee025-1a67-420d-8d00-b240abbf0b5a", "type": 2 }, { "bubbleId": "a818cefe-6c83-49e6-b15f-12687f7b3ed2", "type": 2 }, { "bubbleId": "3600f24e-e2f2-4b20-9c09-6cebf52d8467", "type": 2 }, { "bubbleId": "ac913b1d-c06a-4c6a-84d7-d06aff3cd1a8", "type": 2 }, { "bubbleId": "d9b44b6c-c335-45bd-a66b-e682a7ac27ba", "type": 2 }, { "bubbleId": "dd79204e-fb8e-4a6a-8e1f-0621c803017a", "type": 2 }, { "bubbleId": "9e84a332-392f-4b53-9670-9da986402e6c", "type": 2 }, { "bubbleId": "dacddb71-2c4d-41e2-9e99-ebd7b56933d3", "type": 2 }, { "bubbleId": "8d426d4a-d3b0-409f-889b-ef033feaa48b", "type": 2 }, { "bubbleId": "9f8f9e92-fded-4508-a96b-f24e7ae72b1b", "type": 2 }, { "bubbleId": "bd54577f-84eb-46cd-9426-b3a2abb26d43", "type": 2 }, { "bubbleId": "e60e07ea-feb8-47bf-8e9a-9bd5a090587c", "type": 2 }, { "bubbleId": "cc01c8da-bb5c-4dad-8084-d5829a1284f2", "type": 2 }, { "bubbleId": "859252c9-caaf-4bee-a180-ed24bc533ef0", "type": 1 }, { "bubbleId": "86562abe-bda0-43b4-b8d0-3c135438b60f", "type": 2 }, { "bubbleId": "4c1ac54a-c662-4e23-883f-1591c3652dd2", "type": 2 }, { "bubbleId": "3256a4bd-5a6d-45fe-a396-e00e97e84dfe", "type": 1 }, { "bubbleId": "c38e6712-9283-49b2-b786-29ebde71e7fd", "type": 2 }, { "bubbleId": "6ca198bf-b634-4d83-8176-398a65c8d816", "type": 2 }, { "bubbleId": "e70064c8-11aa-4115-9a33-7ca175a98a7d", "type": 2 }, { "bubbleId": "782b6224-53c8-4f85-b78d-eaeaa96ba10d", "type": 2 }, { "bubbleId": "7ba3099f-c7b9-49ae-8c41-999c2cdb3e92", "type": 2 }, { "bubbleId": "c8fb9ae1-f309-4e30-861a-dcc0864e56f0", "type": 2 }, { "bubbleId": "d6cf424a-8ca7-4629-a134-abade7c89eb9", "type": 2 }, { "bubbleId": "cfd2ce26-4f9d-4a18-995a-9e80763f497b", "type": 2 }, { "bubbleId": "475a0844-d1cb-4dad-b55a-e9b93c1e12ff", "type": 1 }, { "bubbleId": "d9833d34-1e58-4ae0-8492-95cc8c355607", "type": 2 }, { "bubbleId": "c98e277e-5070-4832-98b9-d4cc470c995b", "type": 2 }, { "bubbleId": "2be58e6f-d13e-4f5d-94ec-489f44248323", "type": 1 }, { "bubbleId": "5e03cd26-1d15-4e87-affa-19426d63c703", "type": 2 }, { "bubbleId": "51b81dec-b237-46ce-b99b-8a4672f9ec5b", "type": 2 }, { "bubbleId": "052fbce0-4c55-431b-b477-f75ca7c614b3", "type": 2 }, { "bubbleId": "66b1a8d7-4a7b-4a11-a313-db7e233e5d00", "type": 2 }, { "bubbleId": "39d05ebf-bca2-4869-957f-ff20e1cbdd26", "type": 2 }, { "bubbleId": "f5822428-f73d-44dc-82fd-d549351d874d", "type": 2 }, { "bubbleId": "4ba51dd2-26c6-43df-b0c3-0041b1347745", "type": 2 }, { "bubbleId": "284c5c3f-51c5-493b-896b-668582b2bdf8", "type": 2 }, { "bubbleId": "fc1a7e0b-5688-4d3e-9460-ce66b1b1dcb8", "type": 2 }, { "bubbleId": "9280060c-108a-4848-9b63-d3f70bf5767f", "type": 2 }, { "bubbleId": "e100b695-1391-42a9-99d4-32d104f566b8", "type": 2 }, { "bubbleId": "0ea9ce46-dc6f-459e-be70-95d10ec9d8fc", "type": 2 }, { "bubbleId": "8d527e1a-abe9-47a7-809a-f5758880facc", "type": 1 }, { "bubbleId": "8e8c4d97-1ce2-4799-8c5d-e7a706e647b2", "type": 2 }, { "bubbleId": "52b23bd9-d6d6-4c3d-a548-91c4115f1187", "type": 2 }, { "bubbleId": "fbe97373-8028-4c23-8051-aa874bafa726", "type": 2 }, { "bubbleId": "e56c87c6-a111-4dfa-988c-508bd8d23025", "type": 2 }, { "bubbleId": "19de9ee0-9832-4794-94ad-7fd01e7776c8", "type": 2 }, { "bubbleId": "bd40cc5e-d594-492f-9c69-2f10d6e085f0", "type": 2 }, { "bubbleId": "34b4c55c-1416-4624-9e90-4e4dbf94ae7e", "type": 2 }, { "bubbleId": "77885764-5cc5-49e9-aa29-8f99e1ad91be", "type": 2 }, { "bubbleId": "75930adf-1723-4275-9f72-32b5cb770869", "type": 2 }, { "bubbleId": "161bc6c0-e489-4209-a507-eb8ab2eab0c7", "type": 2 }, { "bubbleId": "e2d87e6f-5ce8-47d9-8fb7-41607132b9c7", "type": 2 }, { "bubbleId": "6486a74e-c56f-4616-83f3-82c140ce1505", "type": 2 }, { "bubbleId": "0f5cd586-b110-45f0-a08b-1c2980651077", "type": 2 }, { "bubbleId": "1a9947b4-e78c-4e0c-b970-78bf2448c539", "type": 2 }, { "bubbleId": "e39e4bd6-6a57-49ef-ba9f-ffa88df07b3c", "type": 2 }, { "bubbleId": "3d364c16-b345-4455-b5e3-d1bebed5e50e", "type": 2 }, { "bubbleId": "cd75e265-c8ca-431d-a44f-e3575ef938ec", "type": 1 }, { "bubbleId": "97ea120a-2752-4eff-8800-1107955e1cef", "type": 2 }, { "bubbleId": "3b02305c-b40e-4253-8c0f-f09279d9adca", "type": 2 }, { "bubbleId": "eca949f4-9095-4a61-b3f7-6a3df9dc65eb", "type": 1 }, { "bubbleId": "683d0188-f9a8-42e5-bef1-ca0525d2e1e1", "type": 2 }, { "bubbleId": "b46f7ac4-7f08-4125-8c36-969c540cb6ba", "type": 2 }, { "bubbleId": "e372205a-4bb1-42ec-8c04-140a6cfe7226", "type": 2 }, { "bubbleId": "03a685d5-56c7-4841-a70a-5c4a1cfd1f63", "type": 2 }, { "bubbleId": "71a13da4-16a2-4fcb-8927-3f19e4bec1f6", "type": 2 }, { "bubbleId": "378bff48-91ef-4ab6-9f84-8f4627e5cdb0", "type": 2 }, { "bubbleId": "f1744b48-0fed-43dd-90b1-718b3a04e8e4", "type": 2 }, { "bubbleId": "62ccbd6f-911e-4703-bd93-b8a3e226c51e", "type": 2 }, { "bubbleId": "a1c0d837-cbd1-4d50-a3e9-b282c6ee182e", "type": 2 }, { "bubbleId": "214eb165-8b4a-41d4-8615-3138b4a45a80", "type": 2 }, { "bubbleId": "70da7214-a7ca-4441-894f-0d488c38c4cb", "type": 2 }, { "bubbleId": "110a76d6-0877-4042-a250-56c116c761eb", "type": 2 }, { "bubbleId": "6c9d1371-f13d-4c1d-8e4e-4340f06910e6", "type": 2 }, { "bubbleId": "02eb6c0e-46f0-4a50-8e5b-8093c7cd3020", "type": 2 }, { "bubbleId": "fe637b17-3216-464f-bf77-48478477d797", "type": 2 }, { "bubbleId": "0e5450dd-2bef-4b89-917c-3c36bbd9ec3c", "type": 1 }, { "bubbleId": "bb9daf5f-a1f7-4d6a-9eb1-d06a8d0b83ae", "type": 2 }, { "bubbleId": "dfc0f138-1ab3-4d9a-b61a-d3f4ac9d573c", "type": 2 }, { "bubbleId": "a85650e3-fcce-4955-a93a-cea05e6950d9", "type": 1 }, { "bubbleId": "3994efc5-5636-4373-b8a6-497213ab4b25", "type": 2 }, { "bubbleId": "fabefd26-2ab8-4238-856a-d71a08c88e13", "type": 2 }, { "bubbleId": "2f9f027a-1c9a-4261-bd7e-db0c79a936ae", "type": 1 }, { "bubbleId": "62df2253-4853-48ec-ae7b-0f6122a2af83", "type": 2 }, { "bubbleId": "67ed4a1d-8990-4e7f-8e60-eabaffb37a2a", "type": 2 }, { "bubbleId": "480d8046-8f9e-4d98-9241-2416228d8dcc", "type": 1 }, { "bubbleId": "2fb1c9db-852b-47eb-b882-84350f483eef", "type": 2 }, { "bubbleId": "e77f3f1e-fe64-45f2-8384-928fc5d51f27", "type": 2 }, { "bubbleId": "7c4ee384-daa0-473e-b46a-5d772acc6496", "type": 2 }, { "bubbleId": "0a2496fe-b1a8-4ec6-a213-58ef394a5696", "type": 2 }, { "bubbleId": "8225bb09-dc6c-405d-b32d-07a74936d279", "type": 2 }, { "bubbleId": "3e0c93b6-3958-4f2d-b3b8-d69d5c2eddc1", "type": 2 }, { "bubbleId": "32d2dda8-7d76-4375-8d5e-dd76edebe807", "type": 2 }, { "bubbleId": "31d03561-91e7-4699-a79b-026d086a9460", "type": 2 }, { "bubbleId": "7aa728d5-677b-4e40-a8c6-0973c07e8b73", "type": 2 }, { "bubbleId": "260aabde-2bef-438c-9656-dd3b41bc2578", "type": 2 }, { "bubbleId": "08cfd30c-f9b4-4c39-b10a-bed5ddb11903", "type": 2 }, { "bubbleId": "61011932-0e1b-4455-bc99-0079005e0cd2", "type": 2 }, { "bubbleId": "90b43864-7694-41e4-be93-e482058656a1", "type": 2 }, { "bubbleId": "352ea863-30cd-4e8f-b7a2-ddbdcfded617", "type": 2 }, { "bubbleId": "e998faf9-9108-4886-8b77-931e72c4562a", "type": 2 }, { "bubbleId": "5ef06089-fe42-4f12-8319-8052af5eb445", "type": 2 }, { "bubbleId": "7a7ba986-3266-4497-8aee-d0cf2432e509", "type": 2 }, { "bubbleId": "6448a3c1-9c6d-48d4-abe1-72a197c85fc0", "type": 2 }, { "bubbleId": "ca7d7730-edef-4be6-8412-1ae67c4b8d64", "type": 2 }, { "bubbleId": "bd95edb2-ccaa-4daf-bf40-f37f6c5c10cd", "type": 2 }, { "bubbleId": "37da15b0-16a9-4221-9924-2f8a30abbfa5", "type": 2 }, { "bubbleId": "58b466ec-397d-43aa-88e2-e3929656fd83", "type": 2 }, { "bubbleId": "0d55d26a-2b11-4f05-b212-9eae268954ae", "type": 2 }, { "bubbleId": "94a4aea3-c369-4713-b2bd-50e80dc629e5", "type": 2 }, { "bubbleId": "33f4c8f0-9d45-4651-bd03-31e7154a2dfb", "type": 2 }, { "bubbleId": "100771a1-7a35-4169-b9c0-53e69046d754", "type": 2 }, { "bubbleId": "0149bf71-7223-4d37-98d8-63069678e7c6", "type": 2 }, { "bubbleId": "72ea8411-4513-41d5-a820-06e3468e0b85", "type": 2 }, { "bubbleId": "ca49ddc7-3d50-4594-af55-de3cbf37b284", "type": 2 }, { "bubbleId": "d13572e7-c513-4bcd-a6fa-a60aeeeed649", "type": 2 }, { "bubbleId": "f525a110-8fc2-4bbc-9068-7a676a7afef3", "type": 2 }, { "bubbleId": "eb593ccb-d934-4172-b77a-18275f5bf053", "type": 2 }, { "bubbleId": "104fcb2b-613a-43c1-9e29-6af05678159d", "type": 2 }, { "bubbleId": "79e4ac41-3448-4090-a59d-08c3ec06eb70", "type": 2 }, { "bubbleId": "94fc91db-f01d-4312-bc3b-4d24d88784f4", "type": 2 }, { "bubbleId": "970009a4-dddb-4dfa-9122-26bb40404e1c", "type": 2 }, { "bubbleId": "ed181675-035d-4e0d-a768-63883960b0d4", "type": 2 }, { "bubbleId": "c9722bde-550e-400c-bf1d-f4b8a127df84", "type": 2 }, { "bubbleId": "1ebf8507-ef43-4054-9a45-8d40bc90f680", "type": 2 }, { "bubbleId": "ba3d5a12-102f-4a92-94c9-247bef616690", "type": 2 }, { "bubbleId": "f8792266-8ca4-4ea6-aebf-8e6366cfc5f7", "type": 2 }, { "bubbleId": "14b8c56c-592a-4139-980f-47a397bb58d6", "type": 2 }, { "bubbleId": "1c543f8b-16fc-4d60-9fa9-3244d7468d7f", "type": 2 }, { "bubbleId": "46ef4e4d-41f5-4748-bcb6-225be305eb83", "type": 2 }, { "bubbleId": "aadcafd9-26f0-49cb-973c-58044f355b35", "type": 2 }, { "bubbleId": "4f0844ce-4fcb-4e9f-8aee-5a9df27c8099", "type": 2 }, { "bubbleId": "1d84a503-3ac8-4a01-8769-1e15b31dbaa5", "type": 2 }, { "bubbleId": "bbb21013-4a6f-4e3a-b9fc-88fe3d83d120", "type": 2 }, { "bubbleId": "c710b03e-519d-4784-bb95-3d24144f22a3", "type": 1 }, { "bubbleId": "0840707e-43b4-4962-ae5f-87369d07ad6e", "type": 2 }, { "bubbleId": "c4147f56-8e29-489d-a714-cbe720437b9b", "type": 2 } ], "conversationMap": {}, "status": "completed", "context": { "composers": [], "selectedCommits": [], "selectedPullRequests": [], "selectedImages": [], "folderSelections": [], "fileSelections": [], "selections": [], "terminalSelections": [], "selectedDocs": [], "externalLinks": [], "cursorRules": [], "cursorCommands": [], "gitPRDiffSelections": [], "subagentSelections": [], "browserSelections": [], "mentions": { "composers": {}, "selectedCommits": {}, "selectedPullRequests": {}, "gitDiff": [], "gitDiffFromBranchToMain": [], "selectedImages": {}, "folderSelections": { "{\"relativePath\":\"common/trivy-operator\",\"addedWithoutMention\":false}": [] }, "fileSelections": {}, "terminalFiles": {}, "selections": {}, "terminalSelections": { "{\"uri\":\"vscode-terminal:/home-ruslanpi-Documents-repos-lmru-devops-argocd-apps/1\",\"range\":{\"startLineNumber\":7,\"startColumn\":1,\"endLineNumber\":13,\"endColumn\":74,\"selectionStartLineNumber\":7,\"selectionStartColumn\":1,\"positionLineNumber\":13,\"positionColumn\":74},\"text\":\"```bash\\n' | sort -V\\n4.2.8 FAIL=6 HIGH Ensure that the --hostname-override argument is not set\\n5.2.2 FAIL=10 HIGH Minimize the admission of privileged containers\\n5.2.3 FAIL=2 HIGH Minimize the admission of containers wishing to share the host process ID namespace\\n5.2.5 FAIL=38 HIGH Minimize the admission of containers wishing to share the host network namespace\\n5.2.13 FAIL=2 MEDIUM Minimize the admission of containers which use HostPorts\\n5.7.3 FAIL=4 HIGH Apply Security Context to Your Pods and Containers\\n```\"}": [ { "uuid": "dc9d7f22-8577-463e-be36-d58d1f41c6b0" } ] }, "selectedDocs": {}, "externalLinks": { "https://github.com/giantswarm/starboard-exporter": [ { "uuid": "1077" } ], "https://aquasecurity.github.io/trivy-operator/v0.25.0/getting-started/installation/configuration/": [ { "uuid": "1085" } ] }, "diffHistory": [], "cursorRules": {}, "cursorCommands": {}, "uiElementSelections": [], "consoleLogs": [], "ideEditorsState": [], "gitPRDiffSelections": {}, "subagentSelections": {}, "browserSelections": {} } }, "generatingBubbleIds": [], "isReadingLongFile": false, "codeBlockData": {}, "originalFileStates": { "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/values/values-global.yaml": { "content": "# Default values for the trivy-operator Helm chart, these are used to render\n# the templates into valid k8s Resources.\n\n# -- global values provide a centralized configuration for 'image.registry', reducing the potential for errors.\n# If left blank, the chart will default to the individually set 'image.registry' values\nglobal:\n image:\n registry: \"docker-security.art.lmru.tech\"\n\n# -- managedBy is similar to .Release.Service but allows to overwrite the value\nmanagedBy: Helm\n\n# -- targetNamespace defines where you want trivy-operator to operate. By\n# default, it's a blank string to select all namespaces, but you can specify\n# another namespace, or a comma separated list of namespaces.\ntargetNamespaces: \"\"\n\n# -- excludeNamespaces is a comma separated list of namespaces (or glob patterns)\n# to be excluded from scanning. Only applicable in the all namespaces install\n# mode, i.e. when the targetNamespaces values is a blank string.\nexcludeNamespaces:\n#- kube-system\n- kube-public\n- kube-node-lease\n- ingress-nginx\n\n# -- extraEnv is a list of extra environment variables for the trivy-operator.\nextraEnv: []\n\n# -- hostAliases for `deployment` (TrivyOperator) and `statefulset` (TrivyServer)\n\nhostAliases: []\n# - ip: \"127.0.0.1\"\n# hostnames:\n# - \"foo.local\"\n# - \"bar.local\"\n# - ip: \"10.1.2.3\"\n# hostnames:\n# - \"foo.remote\"\n# - \"bar.remote\"\n\n# -- targetWorkloads is a comma seperated list of Kubernetes workload resources\n# to be included in the vulnerability and config-audit scans\n# if left blank, all workload resources will be scanned\ntargetWorkloads: \"pod,replicaset,replicationcontroller,statefulset,daemonset,cronjob,job\"\n\n# -- nameOverride override operator name\nnameOverride: \"\"\n\n# -- fullnameOverride override operator full name\nfullnameOverride: \"trivy-operator\"\n\noperator:\n # -- namespace to install the operator, defaults to the .Release.Namespace\n namespace: \"\"\n # -- replicas the number of replicas of the operator's pod\n replicas: 1\n\n # -- number of old history to retain to allow rollback (if not set, default Kubernetes value is set to 10)\n revisionHistoryLimit: 5\n\n # -- additional annotations for the operator deployment\n annotations: {}\n\n # -- additional labels for the operator deployment\n labels: {}\n\n # -- additional labels for the operator pod\n podLabels:\n prometheus.deckhouse.io/custom-target: trivy-operator\n\n # -- leaderElectionId determines the name of the resource that leader election\n # will use for holding the leader lock.\n leaderElectionId: \"trivyoperator-lock\"\n\n # -- logDevMode the flag to enable development mode (more human-readable output, extra stack traces and logging information, etc)\n logDevMode: false\n\n # -- scanJobTTL the set automatic cleanup time after the job is completed\n scanJobTTL: \"\"\n\n # -- scanSecretTTL set an automatic cleanup for scan job secrets\n scanSecretTTL: \"\"\n\n # -- scanJobTimeout the length of time to wait before giving up on a scan job\n scanJobTimeout: 5m\n\n # -- scanJobsConcurrentLimit the maximum number of scan jobs create by the operator\n scanJobsConcurrentLimit: 5\n\n # -- scanNodeCollectorLimit the maximum number of node collector jobs create by the operator\n scanNodeCollectorLimit: 1\n\n # -- scanJobsRetryDelay the duration to wait before retrying a failed scan job\n scanJobsRetryDelay: 30s\n\n # -- the flag to enable vulnerability scanner\n vulnerabilityScannerEnabled: false\n # -- the flag to enable sbom generation, required for enabling ClusterVulnerabilityReports\n sbomGenerationEnabled: false\n # -- the flag to enable cluster sbom cache generation\n clusterSbomCacheEnabled: false\n # -- scannerReportTTL the flag to set how long a report should exist. \"\" means that the ScannerReportTTL feature is disabled\n scannerReportTTL: \"20h\"\n # -- cacheReportTTL the flag to set how long a cluster sbom report should exist. \"\" means that the cacheReportTTL feature is disabled\n cacheReportTTL: \"48h\"\n # -- configAuditScannerEnabled the flag to enable configuration audit scanner\n configAuditScannerEnabled: true\n # -- rbacAssessmentScannerEnabled the flag to enable rbac assessment scanner\n rbacAssessmentScannerEnabled: false\n # -- infraAssessmentScannerEnabled the flag to enable infra assessment scanner\n infraAssessmentScannerEnabled: true\n # -- clusterComplianceEnabled the flag to enable cluster compliance scanner\n clusterComplianceEnabled: true\n # -- batchDeleteLimit the maximum number of config audit reports deleted by the operator when the plugin's config has changed.\n batchDeleteLimit: 10\n # -- vulnerabilityScannerScanOnlyCurrentRevisions the flag to only create vulnerability scans on the current revision of a deployment.\n vulnerabilityScannerScanOnlyCurrentRevisions: false\n # -- configAuditScannerScanOnlyCurrentRevisions the flag to only create config audit scans on the current revision of a deployment.\n configAuditScannerScanOnlyCurrentRevisions: true\n # -- batchDeleteDelay the duration to wait before deleting another batch of config audit reports.\n batchDeleteDelay: 10s\n # -- accessGlobalSecretsAndServiceAccount The flag to enable access to global secrets/service accounts to allow `vulnerability scan job` to pull images from private registries\n accessGlobalSecretsAndServiceAccount: false\n # -- builtInTrivyServer The flag enables the usage of built-in trivy server in cluster. It also overrides the following trivy params with built-in values\n # trivy.mode = ClientServer and serverURL = http://.:4975\n builtInTrivyServer: false\n # -- builtInServerRegistryInsecure is the flag to enable insecure connection from the built-in Trivy server to the registry.\n builtInServerRegistryInsecure: false\n # -- controllerCacheSyncTimeout the duration to wait for controller resources cache sync (default: 5m).\n controllerCacheSyncTimeout: \"5m\"\n\n # -- trivyServerHealthCheckCacheExpiration The flag to set the interval for trivy server health cache before it invalidate\n trivyServerHealthCheckCacheExpiration: 10h\n\n # -- metricsFindingsEnabled the flag to enable metrics for findings\n metricsFindingsEnabled: true\n\n # -- metricsVulnIdEnabled the flag to enable metrics about cve vulns id\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsVulnIdEnabled: false\n\n # -- exposedSecretScannerEnabled the flag to enable exposed secret scanner\n exposedSecretScannerEnabled: false\n\n # -- MetricsExposedSecretInfo the flag to enable metrics about exposed secrets\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsExposedSecretInfo: false\n\n # -- MetricsConfigAuditInfo the flag to enable metrics about configuration audits\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsConfigAuditInfo: false\n\n # -- MetricsRbacAssessmentInfo the flag to enable metrics about Rbac Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsRbacAssessmentInfo: false\n\n # -- MetricsInfraAssessmentInfo the flag to enable metrics about Infra Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsInfraAssessmentInfo: false\n\n # -- MetricsImageInfo the flag to enable metrics about Image Information of scanned images\n # This information has image os information including os family, name/version, and if end of service life has been reached\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsImageInfo: false\n\n # -- MetricsClusterComplianceInfo the flag to enable metrics about Cluster Compliance\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsClusterComplianceInfo: true\n\n # -- serverAdditionalAnnotations the flag to set additional annotations for the trivy server pod\n serverAdditionalAnnotations: {}\n\n # -- webhookBroadcastURL the flag to set reports should be sent to a webhook endpoint. \"\" means that the webhookBroadcastURL feature is disabled\n webhookBroadcastURL: \"\"\n\n # -- webhookBroadcastTimeout the flag to set timeout for webhook requests if webhookBroadcastURL is enabled\n webhookBroadcastTimeout: 30s\n\n # -- webhookBroadcastCustomHeaders the flag to set webhook endpoint sent with custom defined headers if webhookBroadcastURL is enabled\n webhookBroadcastCustomHeaders: \"\"\n\n # -- webhookSendDeletedReports the flag to enable sending deleted reports if webhookBroadcastURL is enabled\n webhookSendDeletedReports: false\n\n # -- privateRegistryScanSecretsNames is map of namespace:secrets, secrets are comma seperated which can be used to authenticate in private registries in case if there no imagePullSecrets provided example : {\"mynamespace\":\"mySecrets,anotherSecret\"}\n privateRegistryScanSecretsNames: {}\n\n # -- mergeRbacFindingWithConfigAudit the flag to enable merging rbac finding with config-audit report\n mergeRbacFindingWithConfigAudit: false\n\n # -- httpProxy is the HTTP proxy used by Trivy operator to download the default policies from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy operator to download the default policies from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply OPERATOR_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply OPERATOR_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\nimage:\n registry: \"mirror.gcr.io\"\n repository: \"aquasec/trivy-operator\"\n # -- tag is an override of the image tag, which is by default set by the\n # appVersion field in Chart.yaml.\n tag: \"\"\n # -- pullPolicy set the operator pullPolicy\n pullPolicy: IfNotPresent\n # -- pullSecrets set the operator pullSecrets\n pullSecrets: []\n\n# -- service only expose a metrics endpoint for prometheus to scrape,\n# trivy-operator does not have a user interface.\nservice:\n # -- if true, the Service doesn't allocate any IP\n headless: false\n # -- port exposed by the Service\n metricsPort: 80\n # -- annotations added to the operator's service\n annotations: {}\n # -- appProtocol of the monitoring service\n metricsAppProtocol: TCP\n # -- the Service type\n type: ClusterIP\n # -- the nodeport to use when service type is LoadBalancer or NodePort. If not set, Kubernetes automatically select one.\n nodePort:\n\n # -- Prometheus ServiceMonitor configuration -- to install the trivy operator with the ServiceMonitor\n # you must have Prometheus already installed and running. If you do not have Prometheus installed, enabling this will\n # have no effect.\nserviceMonitor:\n # -- enabled determines whether a serviceMonitor should be deployed\n enabled: false\n # -- The namespace where Prometheus expects to find service monitors\n namespace: ~\n # -- Interval at which metrics should be scraped. If not specified Prometheus’ global scrape interval is used.\n interval: ~\n # -- Additional annotations for the serviceMonitor\n annotations: {}\n # -- Additional labels for the serviceMonitor\n labels: {}\n # -- HonorLabels chooses the metric’s labels on collisions with target labels\n honorLabels: true\n # -- EndpointAdditionalProperties allows setting additional properties on the endpoint such as relabelings, metricRelabelings etc.\n endpointAdditionalProperties: {}\n\nreportMetrics:\n enabled: true\n image:\n registry: registry.k8s.io\n repository: kube-state-metrics\n tag: 2.18.0\n pullPolicy: IfNotPresent\n serviceAccount:\n create: true\n name: \"\"\n podAnnotations: {}\n podLabels: {}\n service:\n customTarget: custom-trivy-kube-state-metrics\n port: 8080\n path: /metrics\n sampleLimit: 15000\n resources:\n requests:\n cpu: 50m\n memory: 128Mi\n limits:\n cpu: 200m\n memory: 256Mi\n\ntrivyOperator:\n # -- vulnerabilityReportsPlugin the name of the plugin that generates vulnerability reports `Trivy`\n vulnerabilityReportsPlugin: \"Trivy\"\n # -- configAuditReportsPlugin the name of the plugin that generates config audit reports.\n configAuditReportsPlugin: \"Trivy\"\n # -- scanJobCompressLogs control whether scanjob output should be compressed or plain\n scanJobCompressLogs: false\n # -- scanJobAffinity affinity to be applied to the scanner pods and node-collector\n scanJobAffinity: {}\n # -- scanJobTolerations tolerations to be applied to the scanner pods so that they can run on nodes with matching taints\n scanJobTolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- scanJobNodeSelector nodeSelector to be applied to the scanner pods so that they can run on nodes with matching labels\n scanJobNodeSelector: {}\n # -- If you do want to specify nodeSelector, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobNodeSelector:'.\n # nodeType: worker\n # cpu: sandylake\n # teamOwner: operators\n\n # -- scanJobCustomVolumesMount add custom volumes mount to the scan job\n scanJobCustomVolumesMount: []\n # - name: var-lib-etcd\n # mountPath: /var/lib/etcd\n # readOnly: true\n\n # -- scanJobCustomVolumes add custom volumes to the scan job\n scanJobCustomVolumes: []\n # - name: var-lib-etcd\n # hostPath:\n # path: /var/lib/etcd\n\n # -- useGCRServiceAccount the flag to enable the usage of GCR service account for scanning images in GCR\n useGCRServiceAccount: true\n # -- scanJobAutomountServiceAccountToken the flag to enable automount for service account token on scan job\n scanJobAutomountServiceAccountToken: false\n\n # -- scanJobAnnotations comma-separated representation of the annotations which the user wants the scanner jobs and pods to be\n # annotated with. Example: `foo=bar,env=stage` will annotate the scanner jobs and pods with the annotations `foo: bar` and `env: stage`\n scanJobAnnotations: \"\"\n\n # -- scanJobPodTemplateLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the scanner pods with the labels `foo: bar` and `env: stage`\n scanJobPodTemplateLabels: \"\"\n\n # -- skipInitContainers when this flag is set to true, the initContainers will be skipped for the scanner and node collector pods\n skipInitContainers: false\n\n # -- scanJobPodTemplatePodSecurityContext podSecurityContext the user wants the scanner and node collector pods to be amended with.\n # Example:\n # RunAsUser: 10000\n # RunAsGroup: 10000\n # RunAsNonRoot: true\n scanJobPodTemplatePodSecurityContext: {}\n\n # -- scanJobPodTemplateContainerSecurityContext SecurityContext the user wants the scanner and node collector containers (and their\n # initContainers) to be amended with.\n scanJobPodTemplateContainerSecurityContext:\n allowPrivilegeEscalation: false\n capabilities:\n drop:\n - ALL\n privileged: false\n readOnlyRootFilesystem: true\n # -- For filesystem scanning, Trivy needs to run as the root user\n # runAsUser: 0\n\n # -- scanJobPodPriorityClassName Priority class name to be set on the pods created by trivy operator jobs. This accepts a string value\n scanJobPodPriorityClassName: \"\"\n\n # -- reportResourceLabels comma-separated scanned resource labels which the user wants to include in the Prometheus\n # metrics report. Example: `owner,app`\n reportResourceLabels: \"\"\n\n # -- reportRecordFailedChecksOnly flag is to record only failed checks on misconfiguration reports (config-audit and rbac assessment)\n reportRecordFailedChecksOnly: true\n\n # -- skipResourceByLabels comma-separated labels keys which trivy-operator will skip scanning on resources with matching labels\n skipResourceByLabels: \"\"\n\n # -- metricsResourceLabelsPrefix Prefix that will be prepended to the labels names indicated in `reportResourceLabels`\n # when including them in the Prometheus metrics\n metricsResourceLabelsPrefix: \"k8s_label_\"\n\n # -- additionalReportLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the reports with the labels `foo: bar` and `env: stage`\n additionalReportLabels: \"\"\n\n # -- policiesConfig Custom Rego Policies to be used by the config audit scanner\n # See https://github.com/aquasecurity/trivy-operator/blob/main/docs/tutorials/writing-custom-configuration-audit-policies.md for more details.\n policiesConfig: \"\"\n\n # -- excludeImages is comma separated glob patterns for excluding images from scanning.\n # Example: pattern: `k8s.gcr.io/*/*` will exclude image: `k8s.gcr.io/coredns/coredns:v1.8.0`.\n excludeImages: \"\"\n\ntrivy:\n # -- createConfig indicates whether to create config objects\n createConfig: true\n image:\n # -- registry of the Trivy image\n registry: mirror.gcr.io\n # -- repository of the Trivy image\n repository: aquasec/trivy\n # -- tag version of the Trivy image\n tag: 0.60.0\n # -- imagePullSecret is the secret name to be used when pulling trivy image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n\n # -- pullPolicy is the imge pull policy used for trivy image , valid values are (Always, Never, IfNotPresent)\n pullPolicy: IfNotPresent\n\n # -- mode is the Trivy client mode. Either Standalone or ClientServer. Depending\n # on the active mode other settings might be applicable or required.\n mode: Standalone\n\n # -- sbomSources trivy will try to retrieve SBOM from the specified sources (oci,rekor)\n sbomSources: \"\"\n\n # -- includeDevDeps include development dependencies in the report (supported: npm, yarn) (default: false)\n # note: this flag is only applicable when trivy.command is set to filesystem\n includeDevDeps: false\n\n # -- whether to use a storage class for trivy server or emptydir (one mey want to use ephemeral storage)\n storageClassEnabled: true\n\n # -- storageClassName is the name of the storage class to be used for trivy server PVC. If empty, tries to find default storage class\n storageClassName: \"\"\n\n # -- storageSize is the size of the trivy server PVC\n storageSize: \"5Gi\"\n\n # -- labels is the extra labels to be used for trivy server statefulset\n labels: {}\n\n # -- podLabels is the extra pod labels to be used for trivy server\n podLabels: {}\n\n # -- priorityClassName is the name of the priority class used for trivy server\n priorityClassName: \"\"\n\n # -- additionalVulnerabilityReportFields is a comma separated list of additional fields which\n # can be added to the VulnerabilityReport. Supported parameters: Description, Links, CVSS, Target, Class, PackagePath and PackageType\n additionalVulnerabilityReportFields: \"\"\n\n # -- httpProxy is the HTTP proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- Registries without SSL. There can be multiple registries with different keys.\n nonSslRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- sslCertDir can be used to override the system default locations for SSL certificate files directory, example: /ssl/certs\n sslCertDir: ~\n\n # -- The registry to which insecure connections are allowed. There can be multiple registries with different keys.\n insecureRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- Mirrored registries. There can be multiple registries with different keys.\n # Make sure to quote registries containing dots\n registry:\n mirror: {}\n # \"docker.io\": docker-mirror.example.com\n\n # -- severity is a comma separated list of severity levels reported by Trivy.\n severity: UNKNOWN,HIGH,CRITICAL\n\n # -- slow this flag is to use less CPU/memory for scanning though it takes more time than normal scanning. It fits small-footprint\n slow: true\n # -- ignoreUnfixed is the flag to show only fixed vulnerabilities in\n # vulnerabilities reported by Trivy. Set to true to enable it.\n #\n ignoreUnfixed: true\n # -- a comma separated list of file paths for Trivy to skip\n skipFiles: # -- a comma separated list of directories for Trivy to skip\n\n skipDirs:\n\n # -- offlineScan is the flag to enable the offline scan functionality in Trivy\n # This will prevent outgoing HTTP requests, e.g. to search.maven.org\n offlineScan: false\n\n # -- timeout is the duration to wait for scan completion.\n timeout: \"5m0s\"\n\n # -- ignoreFile can be used to tell Trivy to ignore vulnerabilities by ID (one per line)\n ignoreFile: ~\n # ignoreFile:\n # - CVE-1970-0001\n # - CVE-1970-0002\n\n # -- ignorePolicy can be used to tell Trivy to ignore vulnerabilities by a policy\n # If multiple policies would match, then the most specific one has precedence over the others.\n # See https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#by-open-policy-agent for more details.\n # See https://github.com/aquasecurity/trivy/blob/v0.19.2/contrib/example_policy/basic.rego for more details on ignorePolicy filtering.\n #\n # ignorePolicy.application.my-app-.: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"application\" with the name pattern \"my-app-*\"\n # ignorePolicy.kube-system: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"kube-system\"\n # ignorePolicy: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all other workloads\n\n # -- vulnType can be used to tell Trivy to filter vulnerabilities by a pkg-type (library, os)\n vulnType: ~\n\n # -- resources resource requests and limits for scan job containers\n resources:\n requests:\n cpu: 100m\n memory: 100M\n # ephemeralStorage: \"2Gi\"\n limits:\n cpu: 500m\n memory: 1Gi\n # ephemeralStorage: \"2Gi\"\n\n # -- githubToken is the GitHub access token used by Trivy to download the vulnerabilities\n # database from GitHub. Only applicable in Standalone mode.\n githubToken: ~\n\n # -- serverURL is the endpoint URL of the Trivy server. Required in ClientServer mode.\n #\n # serverURL: \"https://trivy.trivy:4975\"\n\n # -- clientServerSkipUpdate is the flag to enable skip databases update for Trivy client.\n # Only applicable in ClientServer mode.\n clientServerSkipUpdate: false\n\n # -- skipJavaDBUpdate is the flag to enable skip Java index databases update for Trivy client.\n skipJavaDBUpdate: false\n\n # -- serverInsecure is the flag to enable insecure connection to the Trivy server.\n serverInsecure: false\n\n # -- serverToken is the token to authenticate Trivy client with Trivy server. Only\n # applicable in ClientServer mode.\n serverToken: ~\n\n # -- existingSecret if a secret containing gitHubToken, serverToken or serverCustomHeaders has been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: trivy.githubToken, trivy.serverToken, trivy.serverCustomHeaders\n # Overrides trivy.gitHubToken, trivy.serverToken, trivy.serverCustomHeaders values.\n # Note: The secret has to be named \"trivy-operator-trivy-config\".\n # existingSecret: true\n\n # -- serverTokenHeader is the name of the HTTP header used to send the authentication\n # token to Trivy server. Only application in ClientServer mode when\n # trivy.serverToken is specified.\n serverTokenHeader: \"Trivy-Token\"\n\n # -- serverCustomHeaders is a comma separated list of custom HTTP headers sent by\n # Trivy client to Trivy server. Only applicable in ClientServer mode.\n serverCustomHeaders: ~\n # serverCustomHeaders: \"foo=bar\"\n\n dbRegistry: \"mirror.gcr.io\"\n dbRepository: \"aquasec/trivy-db\"\n\n # -- The username for dbRepository authentication\n #\n dbRepositoryUsername: ~\n\n # -- The password for dbRepository authentication\n #\n dbRepositoryPassword: ~\n\n # -- javaDbRegistry is the registry for the Java vulnerability database.\n javaDbRegistry: \"mirror.gcr.io\"\n javaDbRepository: \"aquasec/trivy-java-db\"\n\n # -- The Flag to enable insecure connection for downloading trivy-db via proxy (air-gaped env)\n #\n dbRepositoryInsecure: \"false\"\n\n # -- The Flag to enable the usage of builtin rego policies by default, these policies are downloaded by default from mirror.gcr.io/aquasec/trivy-checks\n #\n useBuiltinRegoPolicies: \"false\"\n # -- The Flag to enable the usage of external rego policies config-map, this should be used when the user wants to use their own rego policies\n #\n externalRegoPoliciesEnabled: false\n # -- To enable the usage of embedded rego policies, set the flag useEmbeddedRegoPolicies. This should serve as a fallback for air-gapped environments.\n # When useEmbeddedRegoPolicies is set to true, useBuiltinRegoPolicies should be set to false.\n useEmbeddedRegoPolicies: \"true\"\n\n # -- The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner\n #\n supportedConfigAuditKinds: \"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota\"\n\n # -- command. One of `image`, `filesystem` or `rootfs` scanning, depending on the target type required for the scan.\n # For 'filesystem' and `rootfs` scanning, ensure that the `trivyOperator.scanJobPodTemplateContainerSecurityContext` is configured\n # to run as the root user (runAsUser = 0).\n command: image\n # -- imageScanCacheDir the flag to set custom path for trivy image scan `cache-dir` parameter.\n # Only applicable in image scan mode.\n imageScanCacheDir: \"/tmp/trivy/.cache\"\n # -- filesystemScanCacheDir the flag to set custom path for trivy filesystem scan `cache-dir` parameter.\n # Only applicable in filesystem scan mode.\n filesystemScanCacheDir: \"/var/trivyoperator/trivy-db\"\n # -- serverUser this param is the server user to be used to download db from private registry\n serverUser: \"\"\n # -- serverPassword this param is the server user to be used to download db from private registry\n serverPassword: \"\"\n # -- serverServiceName this param is the server service name to be used in cluster\n serverServiceName: \"trivy-service\"\n # -- debug One of `true` or `false`. Enables debug mode.\n debug: false\n\n server:\n # -- resources set trivy-server resource\n resources:\n requests:\n cpu: 200m\n memory: 512Mi\n # ephemeral-storage: \"2Gi\"\n limits:\n cpu: 1\n memory: 1Gi\n # ephemeral-storage: \"2Gi\"\n\n # -- podSecurityContext set trivy-server podSecurityContext\n podSecurityContext:\n runAsUser: 65534\n runAsNonRoot: true\n fsGroup: 65534\n\n # -- securityContext set trivy-server securityContext\n securityContext:\n privileged: false\n readOnlyRootFilesystem: true\n\n # -- the number of replicas of the trivy-server\n replicas: 1\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply TRIVY_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply TRIVY_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\ncompliance:\n # -- failEntriesLimit the flag to limit the number of fail entries per control check in the cluster compliance detail report\n # this limit is for preventing the report from being too large per control checks\n failEntriesLimit: 10\n # -- reportType this flag control the type of report generated (summary or all)\n reportType: all\n # -- cron this flag control the cron interval for compliance report generation\n cron: 0 */6 * * *\n # -- specs is a list of compliance specs to be used by the cluster compliance scanner\n # - k8s-cis-1.23\n # - k8s-nsa-1.0\n # - k8s-pss-baseline-0.1\n # - k8s-pss-restricted-0.1\n # - eks-cis-1.4\n # - rke2-cis-1.24\n specs:\n - k8s-cis-1.23\n - k8s-nsa-1.0\n - k8s-pss-baseline-0.1\n - k8s-pss-restricted-0.1\n\nrbac:\n create: true\nserviceAccount:\n # -- Specifies whether a service account should be created.\n create: true\n annotations: {}\n # -- name specifies the name of the k8s Service Account. If not set and create is\n # true, a name is generated using the fullname template.\n name: \"\"\n\n# -- podAnnotations annotations added to the operator's pod\npodAnnotations:\n prometheus.deckhouse.io/port: \"8080\"\n\npodSecurityContext: {}\n# fsGroup: 2000\n\n# -- securityContext security context\nsecurityContext:\n privileged: false\n allowPrivilegeEscalation: false\n readOnlyRootFilesystem: true\n capabilities:\n drop:\n - ALL\n\nvolumeMounts:\n# do not remove , required for policies bundle\n- mountPath: /tmp\n name: cache-policies\n readOnly: false\n\nvolumes:\n# do not remove , required for policies bundle\n- name: cache-policies\n emptyDir: {}\n\nresources: {}\n# -- We usually recommend not to specify default resources and to leave this as a conscious\n# choice for the user. This also increases chances charts run on environments with little\n# resources, such as Minikube. If you do want to specify resources, uncomment the following\n# lines, adjust them as necessary, and remove the curly braces after 'resources:'.\n# limits:\n# cpu: 100m\n# memory: 128Mi\n# requests:\n# cpu: 100m\n# memory: 128Mi\n\n# -- nodeSelector set the operator nodeSelector\n#nodeSelector: {}\n\nnodeSelector:\n node-role.k8s.lmru.tech/application: ''\n\n# -- tolerations set the operator tolerations\ntolerations: []\n\n# -- affinity set the operator affinity\naffinity: {}\n\n# -- priorityClassName set the operator priorityClassName\npriorityClassName: \"\"\n\n# -- automountServiceAccountToken the flag to enable automount for service account token\nautomountServiceAccountToken: true\n\npoliciesBundle:\n # -- registry of the policies bundle\n registry: mirror.gcr.io\n # -- repository of the policies bundle\n repository: aquasec/trivy-checks\n # -- tag version of the policies bundle\n tag: 1\n # -- registryUser is the user for the registry\n registryUser: ~\n # -- registryPassword is the password for the registry\n registryPassword: ~\n # -- existingSecret if a secret containing registry credentials that have been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: policies.bundle.oci.user, policies.bundle.oci.password\n # Overrides policiesBundle.registryUser, policiesBundle.registryPassword values.\n # Note: The secret has to be named \"trivy-operator\".\n existingSecret: false\n # -- insecure is the flag to enable insecure connection to the policy bundle registry\n insecure: false\n\nnodeCollector:\n # -- useNodeSelector determine if to use nodeSelector (by auto detecting node name) with node-collector scan job\n useNodeSelector: false\n # -- registry of the node-collector image\n registry: docker-security.art.lmru.tech\n # -- repository of the node-collector image\n repository: aquasec/node-collector\n # -- tag version of the node-collector image\n tag: 0.3.1\n # -- imagePullSecret is the secret name to be used when pulling node-collector image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n # -- excludeNodes comma-separated node labels that the node-collector job should exclude from scanning (example kubernetes.io/arch=arm64,team=dev)\n excludeNodes: # -- tolerations to be applied to the node-collector so that they can run on nodes with matching taints\n\n tolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- node-collector pod volume mounts definition for collecting config files information\n volumeMounts:\n - name: var-lib-etcd\n mountPath: /var/lib/etcd\n readOnly: true\n - name: var-lib-kubelet\n mountPath: /var/lib/kubelet\n readOnly: true\n - name: var-lib-kube-scheduler\n mountPath: /var/lib/kube-scheduler\n readOnly: true\n - name: var-lib-kube-controller-manager\n mountPath: /var/lib/kube-controller-manager\n readOnly: true\n - name: etc-systemd\n mountPath: /etc/systemd\n readOnly: true\n - name: lib-systemd\n mountPath: /lib/systemd/\n readOnly: true\n - name: etc-kubernetes\n mountPath: /etc/kubernetes\n readOnly: true\n - name: etc-cni-netd\n mountPath: /etc/cni/net.d/\n readOnly: true\n # -- node-collector pod volumes definition for collecting config files information\n volumes:\n - name: var-lib-etcd\n hostPath:\n path: /var/lib/etcd\n - name: var-lib-kubelet\n hostPath:\n path: /var/lib/kubelet\n - name: var-lib-kube-scheduler\n hostPath:\n path: /var/lib/kube-scheduler\n - name: var-lib-kube-controller-manager\n hostPath:\n path: /var/lib/kube-controller-manager\n - name: etc-systemd\n hostPath:\n path: /etc/systemd\n - name: lib-systemd\n hostPath:\n path: /lib/systemd\n - name: etc-kubernetes\n hostPath:\n path: /etc/kubernetes\n - name: etc-cni-netd\n hostPath:\n path: /etc/cni/net.d/\n", "firstEditBubbleId": "f5822428-f73d-44dc-82fd-d549351d874d", "isNewlyCreated": false, "newlyCreatedFolders": [] }, "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/values/values-global.yaml": { "content": "# Default values for the trivy-operator Helm chart, these are used to render\n# the templates into valid k8s Resources.\n\n# -- global values provide a centralized configuration for 'image.registry', reducing the potential for errors.\n# If left blank, the chart will default to the individually set 'image.registry' values\nglobal:\n image:\n registry: \"docker-security.art.lmru.tech\"\n\n# -- managedBy is similar to .Release.Service but allows to overwrite the value\nmanagedBy: Helm\n\n# -- targetNamespace defines where you want trivy-operator to operate. By\n# default, it's a blank string to select all namespaces, but you can specify\n# another namespace, or a comma separated list of namespaces.\ntargetNamespaces: \"\"\n\n# -- excludeNamespaces is a comma separated list of namespaces (or glob patterns)\n# to be excluded from scanning. Only applicable in the all namespaces install\n# mode, i.e. when the targetNamespaces values is a blank string.\nexcludeNamespaces:\n#- kube-system\n- kube-public\n- kube-node-lease\n- ingress-nginx\n\n# -- extraEnv is a list of extra environment variables for the trivy-operator.\nextraEnv: []\n\n# -- hostAliases for `deployment` (TrivyOperator) and `statefulset` (TrivyServer)\n\nhostAliases: []\n# - ip: \"127.0.0.1\"\n# hostnames:\n# - \"foo.local\"\n# - \"bar.local\"\n# - ip: \"10.1.2.3\"\n# hostnames:\n# - \"foo.remote\"\n# - \"bar.remote\"\n\n# -- targetWorkloads is a comma seperated list of Kubernetes workload resources\n# to be included in the vulnerability and config-audit scans\n# if left blank, all workload resources will be scanned\ntargetWorkloads: \"pod,replicaset,replicationcontroller,statefulset,daemonset,cronjob,job\"\n\n# -- nameOverride override operator name\nnameOverride: \"\"\n\n# -- fullnameOverride override operator full name\nfullnameOverride: \"trivy-operator\"\n\noperator:\n # -- namespace to install the operator, defaults to the .Release.Namespace\n namespace: \"\"\n # -- replicas the number of replicas of the operator's pod\n replicas: 1\n\n # -- number of old history to retain to allow rollback (if not set, default Kubernetes value is set to 10)\n revisionHistoryLimit: 5\n\n # -- additional annotations for the operator deployment\n annotations: {}\n\n # -- additional labels for the operator deployment\n labels: {}\n\n # -- additional labels for the operator pod\n podLabels:\n prometheus.deckhouse.io/custom-target: trivy-operator\n\n # -- leaderElectionId determines the name of the resource that leader election\n # will use for holding the leader lock.\n leaderElectionId: \"trivyoperator-lock\"\n\n # -- logDevMode the flag to enable development mode (more human-readable output, extra stack traces and logging information, etc)\n logDevMode: false\n\n # -- scanJobTTL the set automatic cleanup time after the job is completed\n scanJobTTL: \"\"\n\n # -- scanSecretTTL set an automatic cleanup for scan job secrets\n scanSecretTTL: \"\"\n\n # -- scanJobTimeout the length of time to wait before giving up on a scan job\n scanJobTimeout: 5m\n\n # -- scanJobsConcurrentLimit the maximum number of scan jobs create by the operator\n scanJobsConcurrentLimit: 5\n\n # -- scanNodeCollectorLimit the maximum number of node collector jobs create by the operator\n scanNodeCollectorLimit: 1\n\n # -- scanJobsRetryDelay the duration to wait before retrying a failed scan job\n scanJobsRetryDelay: 30s\n\n # -- the flag to enable vulnerability scanner\n vulnerabilityScannerEnabled: false\n # -- the flag to enable sbom generation, required for enabling ClusterVulnerabilityReports\n sbomGenerationEnabled: false\n # -- the flag to enable cluster sbom cache generation\n clusterSbomCacheEnabled: false\n # -- scannerReportTTL the flag to set how long a report should exist. \"\" means that the ScannerReportTTL feature is disabled\n scannerReportTTL: \"20h\"\n # -- cacheReportTTL the flag to set how long a cluster sbom report should exist. \"\" means that the cacheReportTTL feature is disabled\n cacheReportTTL: \"48h\"\n # -- configAuditScannerEnabled the flag to enable configuration audit scanner\n configAuditScannerEnabled: true\n # -- rbacAssessmentScannerEnabled the flag to enable rbac assessment scanner\n rbacAssessmentScannerEnabled: false\n # -- infraAssessmentScannerEnabled the flag to enable infra assessment scanner\n infraAssessmentScannerEnabled: true\n # -- clusterComplianceEnabled the flag to enable cluster compliance scanner\n clusterComplianceEnabled: true\n # -- batchDeleteLimit the maximum number of config audit reports deleted by the operator when the plugin's config has changed.\n batchDeleteLimit: 10\n # -- vulnerabilityScannerScanOnlyCurrentRevisions the flag to only create vulnerability scans on the current revision of a deployment.\n vulnerabilityScannerScanOnlyCurrentRevisions: false\n # -- configAuditScannerScanOnlyCurrentRevisions the flag to only create config audit scans on the current revision of a deployment.\n configAuditScannerScanOnlyCurrentRevisions: true\n # -- batchDeleteDelay the duration to wait before deleting another batch of config audit reports.\n batchDeleteDelay: 10s\n # -- accessGlobalSecretsAndServiceAccount The flag to enable access to global secrets/service accounts to allow `vulnerability scan job` to pull images from private registries\n accessGlobalSecretsAndServiceAccount: false\n # -- builtInTrivyServer The flag enables the usage of built-in trivy server in cluster. It also overrides the following trivy params with built-in values\n # trivy.mode = ClientServer and serverURL = http://.:4975\n builtInTrivyServer: false\n # -- builtInServerRegistryInsecure is the flag to enable insecure connection from the built-in Trivy server to the registry.\n builtInServerRegistryInsecure: false\n # -- controllerCacheSyncTimeout the duration to wait for controller resources cache sync (default: 5m).\n controllerCacheSyncTimeout: \"5m\"\n\n # -- trivyServerHealthCheckCacheExpiration The flag to set the interval for trivy server health cache before it invalidate\n trivyServerHealthCheckCacheExpiration: 10h\n\n # -- metricsFindingsEnabled the flag to enable metrics for findings\n metricsFindingsEnabled: true\n\n # -- metricsVulnIdEnabled the flag to enable metrics about cve vulns id\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsVulnIdEnabled: false\n\n # -- exposedSecretScannerEnabled the flag to enable exposed secret scanner\n exposedSecretScannerEnabled: false\n\n # -- MetricsExposedSecretInfo the flag to enable metrics about exposed secrets\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsExposedSecretInfo: false\n\n # -- MetricsConfigAuditInfo the flag to enable metrics about configuration audits\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsConfigAuditInfo: false\n\n # -- MetricsRbacAssessmentInfo the flag to enable metrics about Rbac Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsRbacAssessmentInfo: false\n\n # -- MetricsInfraAssessmentInfo the flag to enable metrics about Infra Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsInfraAssessmentInfo: false\n\n # -- MetricsImageInfo the flag to enable metrics about Image Information of scanned images\n # This information has image os information including os family, name/version, and if end of service life has been reached\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsImageInfo: false\n\n # -- MetricsClusterComplianceInfo the flag to enable metrics about Cluster Compliance\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsClusterComplianceInfo: true\n\n # -- serverAdditionalAnnotations the flag to set additional annotations for the trivy server pod\n serverAdditionalAnnotations: {}\n\n # -- webhookBroadcastURL the flag to set reports should be sent to a webhook endpoint. \"\" means that the webhookBroadcastURL feature is disabled\n webhookBroadcastURL: \"\"\n\n # -- webhookBroadcastTimeout the flag to set timeout for webhook requests if webhookBroadcastURL is enabled\n webhookBroadcastTimeout: 30s\n\n # -- webhookBroadcastCustomHeaders the flag to set webhook endpoint sent with custom defined headers if webhookBroadcastURL is enabled\n webhookBroadcastCustomHeaders: \"\"\n\n # -- webhookSendDeletedReports the flag to enable sending deleted reports if webhookBroadcastURL is enabled\n webhookSendDeletedReports: false\n\n # -- privateRegistryScanSecretsNames is map of namespace:secrets, secrets are comma seperated which can be used to authenticate in private registries in case if there no imagePullSecrets provided example : {\"mynamespace\":\"mySecrets,anotherSecret\"}\n privateRegistryScanSecretsNames: {}\n\n # -- mergeRbacFindingWithConfigAudit the flag to enable merging rbac finding with config-audit report\n mergeRbacFindingWithConfigAudit: false\n\n # -- httpProxy is the HTTP proxy used by Trivy operator to download the default policies from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy operator to download the default policies from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply OPERATOR_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply OPERATOR_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\nimage:\n registry: \"mirror.gcr.io\"\n repository: \"aquasec/trivy-operator\"\n # -- tag is an override of the image tag, which is by default set by the\n # appVersion field in Chart.yaml.\n tag: \"\"\n # -- pullPolicy set the operator pullPolicy\n pullPolicy: IfNotPresent\n # -- pullSecrets set the operator pullSecrets\n pullSecrets: []\n\n# -- service only expose a metrics endpoint for prometheus to scrape,\n# trivy-operator does not have a user interface.\nservice:\n # -- if true, the Service doesn't allocate any IP\n headless: false\n # -- port exposed by the Service\n metricsPort: 80\n # -- annotations added to the operator's service\n annotations: {}\n # -- appProtocol of the monitoring service\n metricsAppProtocol: TCP\n # -- the Service type\n type: ClusterIP\n # -- the nodeport to use when service type is LoadBalancer or NodePort. If not set, Kubernetes automatically select one.\n nodePort:\n\n # -- Prometheus ServiceMonitor configuration -- to install the trivy operator with the ServiceMonitor\n # you must have Prometheus already installed and running. If you do not have Prometheus installed, enabling this will\n # have no effect.\nserviceMonitor:\n # -- enabled determines whether a serviceMonitor should be deployed\n enabled: false\n # -- The namespace where Prometheus expects to find service monitors\n namespace: ~\n # -- Interval at which metrics should be scraped. If not specified Prometheus’ global scrape interval is used.\n interval: ~\n # -- Additional annotations for the serviceMonitor\n annotations: {}\n # -- Additional labels for the serviceMonitor\n labels: {}\n # -- HonorLabels chooses the metric’s labels on collisions with target labels\n honorLabels: true\n # -- EndpointAdditionalProperties allows setting additional properties on the endpoint such as relabelings, metricRelabelings etc.\n endpointAdditionalProperties: {}\n\nreportMetrics:\n enabled: true\n image:\n registry: registry.k8s.io\n repository: kube-state-metrics\n tag: 2.18.0\n pullPolicy: IfNotPresent\n serviceAccount:\n create: true\n name: \"\"\n podAnnotations: {}\n podLabels: {}\n service:\n customTarget: custom-trivy-kube-state-metrics\n port: 8080\n path: /metrics\n sampleLimit: 15000\n resources:\n requests:\n cpu: 50m\n memory: 128Mi\n limits:\n cpu: 200m\n memory: 256Mi\n\ntrivyOperator:\n # -- vulnerabilityReportsPlugin the name of the plugin that generates vulnerability reports `Trivy`\n vulnerabilityReportsPlugin: \"Trivy\"\n # -- configAuditReportsPlugin the name of the plugin that generates config audit reports.\n configAuditReportsPlugin: \"Trivy\"\n # -- scanJobCompressLogs control whether scanjob output should be compressed or plain\n scanJobCompressLogs: false\n # -- scanJobAffinity affinity to be applied to the scanner pods and node-collector\n scanJobAffinity: {}\n # -- scanJobTolerations tolerations to be applied to the scanner pods so that they can run on nodes with matching taints\n scanJobTolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- scanJobNodeSelector nodeSelector to be applied to the scanner pods so that they can run on nodes with matching labels\n scanJobNodeSelector: {}\n # -- If you do want to specify nodeSelector, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobNodeSelector:'.\n # nodeType: worker\n # cpu: sandylake\n # teamOwner: operators\n\n # -- scanJobCustomVolumesMount add custom volumes mount to the scan job\n scanJobCustomVolumesMount: []\n # - name: var-lib-etcd\n # mountPath: /var/lib/etcd\n # readOnly: true\n\n # -- scanJobCustomVolumes add custom volumes to the scan job\n scanJobCustomVolumes: []\n # - name: var-lib-etcd\n # hostPath:\n # path: /var/lib/etcd\n\n # -- useGCRServiceAccount the flag to enable the usage of GCR service account for scanning images in GCR\n useGCRServiceAccount: true\n # -- scanJobAutomountServiceAccountToken the flag to enable automount for service account token on scan job\n scanJobAutomountServiceAccountToken: false\n\n # -- scanJobAnnotations comma-separated representation of the annotations which the user wants the scanner jobs and pods to be\n # annotated with. Example: `foo=bar,env=stage` will annotate the scanner jobs and pods with the annotations `foo: bar` and `env: stage`\n scanJobAnnotations: \"\"\n\n # -- scanJobPodTemplateLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the scanner pods with the labels `foo: bar` and `env: stage`\n scanJobPodTemplateLabels: \"\"\n\n # -- skipInitContainers when this flag is set to true, the initContainers will be skipped for the scanner and node collector pods\n skipInitContainers: false\n\n # -- scanJobPodTemplatePodSecurityContext podSecurityContext the user wants the scanner and node collector pods to be amended with.\n # Example:\n # RunAsUser: 10000\n # RunAsGroup: 10000\n # RunAsNonRoot: true\n scanJobPodTemplatePodSecurityContext: {}\n\n # -- scanJobPodTemplateContainerSecurityContext SecurityContext the user wants the scanner and node collector containers (and their\n # initContainers) to be amended with.\n scanJobPodTemplateContainerSecurityContext:\n allowPrivilegeEscalation: false\n capabilities:\n drop:\n - ALL\n privileged: false\n readOnlyRootFilesystem: true\n # -- For filesystem scanning, Trivy needs to run as the root user\n # runAsUser: 0\n\n # -- scanJobPodPriorityClassName Priority class name to be set on the pods created by trivy operator jobs. This accepts a string value\n scanJobPodPriorityClassName: \"\"\n\n # -- reportResourceLabels comma-separated scanned resource labels which the user wants to include in the Prometheus\n # metrics report. Example: `owner,app`\n reportResourceLabels: \"\"\n\n # -- reportRecordFailedChecksOnly flag is to record only failed checks on misconfiguration reports (config-audit and rbac assessment)\n reportRecordFailedChecksOnly: true\n\n # -- skipResourceByLabels comma-separated labels keys which trivy-operator will skip scanning on resources with matching labels\n skipResourceByLabels: \"\"\n\n # -- metricsResourceLabelsPrefix Prefix that will be prepended to the labels names indicated in `reportResourceLabels`\n # when including them in the Prometheus metrics\n metricsResourceLabelsPrefix: \"k8s_label_\"\n\n # -- additionalReportLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the reports with the labels `foo: bar` and `env: stage`\n additionalReportLabels: \"\"\n\n # -- policiesConfig Custom Rego Policies to be used by the config audit scanner\n # See https://github.com/aquasecurity/trivy-operator/blob/main/docs/tutorials/writing-custom-configuration-audit-policies.md for more details.\n policiesConfig: \"\"\n\n # -- excludeImages is comma separated glob patterns for excluding images from scanning.\n # Example: pattern: `k8s.gcr.io/*/*` will exclude image: `k8s.gcr.io/coredns/coredns:v1.8.0`.\n excludeImages: \"\"\n\ntrivy:\n # -- createConfig indicates whether to create config objects\n createConfig: true\n image:\n # -- registry of the Trivy image\n registry: mirror.gcr.io\n # -- repository of the Trivy image\n repository: aquasec/trivy\n # -- tag version of the Trivy image\n tag: 0.60.0\n # -- imagePullSecret is the secret name to be used when pulling trivy image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n\n # -- pullPolicy is the imge pull policy used for trivy image , valid values are (Always, Never, IfNotPresent)\n pullPolicy: IfNotPresent\n\n # -- mode is the Trivy client mode. Either Standalone or ClientServer. Depending\n # on the active mode other settings might be applicable or required.\n mode: Standalone\n\n # -- sbomSources trivy will try to retrieve SBOM from the specified sources (oci,rekor)\n sbomSources: \"\"\n\n # -- includeDevDeps include development dependencies in the report (supported: npm, yarn) (default: false)\n # note: this flag is only applicable when trivy.command is set to filesystem\n includeDevDeps: false\n\n # -- whether to use a storage class for trivy server or emptydir (one mey want to use ephemeral storage)\n storageClassEnabled: true\n\n # -- storageClassName is the name of the storage class to be used for trivy server PVC. If empty, tries to find default storage class\n storageClassName: \"\"\n\n # -- storageSize is the size of the trivy server PVC\n storageSize: \"5Gi\"\n\n # -- labels is the extra labels to be used for trivy server statefulset\n labels: {}\n\n # -- podLabels is the extra pod labels to be used for trivy server\n podLabels: {}\n\n # -- priorityClassName is the name of the priority class used for trivy server\n priorityClassName: \"\"\n\n # -- additionalVulnerabilityReportFields is a comma separated list of additional fields which\n # can be added to the VulnerabilityReport. Supported parameters: Description, Links, CVSS, Target, Class, PackagePath and PackageType\n additionalVulnerabilityReportFields: \"\"\n\n # -- httpProxy is the HTTP proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- Registries without SSL. There can be multiple registries with different keys.\n nonSslRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- sslCertDir can be used to override the system default locations for SSL certificate files directory, example: /ssl/certs\n sslCertDir: ~\n\n # -- The registry to which insecure connections are allowed. There can be multiple registries with different keys.\n insecureRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- Mirrored registries. There can be multiple registries with different keys.\n # Make sure to quote registries containing dots\n registry:\n mirror: {}\n # \"docker.io\": docker-mirror.example.com\n\n # -- severity is a comma separated list of severity levels reported by Trivy.\n severity: UNKNOWN,HIGH,CRITICAL\n\n # -- slow this flag is to use less CPU/memory for scanning though it takes more time than normal scanning. It fits small-footprint\n slow: true\n # -- ignoreUnfixed is the flag to show only fixed vulnerabilities in\n # vulnerabilities reported by Trivy. Set to true to enable it.\n #\n ignoreUnfixed: true\n # -- a comma separated list of file paths for Trivy to skip\n skipFiles: # -- a comma separated list of directories for Trivy to skip\n\n skipDirs:\n\n # -- offlineScan is the flag to enable the offline scan functionality in Trivy\n # This will prevent outgoing HTTP requests, e.g. to search.maven.org\n offlineScan: false\n\n # -- timeout is the duration to wait for scan completion.\n timeout: \"5m0s\"\n\n # -- ignoreFile can be used to tell Trivy to ignore vulnerabilities by ID (one per line)\n ignoreFile: ~\n # ignoreFile:\n # - CVE-1970-0001\n # - CVE-1970-0002\n\n # -- ignorePolicy can be used to tell Trivy to ignore vulnerabilities by a policy\n # If multiple policies would match, then the most specific one has precedence over the others.\n # See https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#by-open-policy-agent for more details.\n # See https://github.com/aquasecurity/trivy/blob/v0.19.2/contrib/example_policy/basic.rego for more details on ignorePolicy filtering.\n #\n # ignorePolicy.application.my-app-.: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"application\" with the name pattern \"my-app-*\"\n # ignorePolicy.kube-system: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"kube-system\"\n # ignorePolicy: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all other workloads\n\n # -- vulnType can be used to tell Trivy to filter vulnerabilities by a pkg-type (library, os)\n vulnType: ~\n\n # -- resources resource requests and limits for scan job containers\n resources:\n requests:\n cpu: 100m\n memory: 100M\n # ephemeralStorage: \"2Gi\"\n limits:\n cpu: 500m\n memory: 1Gi\n # ephemeralStorage: \"2Gi\"\n\n # -- githubToken is the GitHub access token used by Trivy to download the vulnerabilities\n # database from GitHub. Only applicable in Standalone mode.\n githubToken: ~\n\n # -- serverURL is the endpoint URL of the Trivy server. Required in ClientServer mode.\n #\n # serverURL: \"https://trivy.trivy:4975\"\n\n # -- clientServerSkipUpdate is the flag to enable skip databases update for Trivy client.\n # Only applicable in ClientServer mode.\n clientServerSkipUpdate: false\n\n # -- skipJavaDBUpdate is the flag to enable skip Java index databases update for Trivy client.\n skipJavaDBUpdate: false\n\n # -- serverInsecure is the flag to enable insecure connection to the Trivy server.\n serverInsecure: false\n\n # -- serverToken is the token to authenticate Trivy client with Trivy server. Only\n # applicable in ClientServer mode.\n serverToken: ~\n\n # -- existingSecret if a secret containing gitHubToken, serverToken or serverCustomHeaders has been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: trivy.githubToken, trivy.serverToken, trivy.serverCustomHeaders\n # Overrides trivy.gitHubToken, trivy.serverToken, trivy.serverCustomHeaders values.\n # Note: The secret has to be named \"trivy-operator-trivy-config\".\n # existingSecret: true\n\n # -- serverTokenHeader is the name of the HTTP header used to send the authentication\n # token to Trivy server. Only application in ClientServer mode when\n # trivy.serverToken is specified.\n serverTokenHeader: \"Trivy-Token\"\n\n # -- serverCustomHeaders is a comma separated list of custom HTTP headers sent by\n # Trivy client to Trivy server. Only applicable in ClientServer mode.\n serverCustomHeaders: ~\n # serverCustomHeaders: \"foo=bar\"\n\n dbRegistry: \"mirror.gcr.io\"\n dbRepository: \"aquasec/trivy-db\"\n\n # -- The username for dbRepository authentication\n #\n dbRepositoryUsername: ~\n\n # -- The password for dbRepository authentication\n #\n dbRepositoryPassword: ~\n\n # -- javaDbRegistry is the registry for the Java vulnerability database.\n javaDbRegistry: \"mirror.gcr.io\"\n javaDbRepository: \"aquasec/trivy-java-db\"\n\n # -- The Flag to enable insecure connection for downloading trivy-db via proxy (air-gaped env)\n #\n dbRepositoryInsecure: \"false\"\n\n # -- The Flag to enable the usage of builtin rego policies by default, these policies are downloaded by default from mirror.gcr.io/aquasec/trivy-checks\n #\n useBuiltinRegoPolicies: \"false\"\n # -- The Flag to enable the usage of external rego policies config-map, this should be used when the user wants to use their own rego policies\n #\n externalRegoPoliciesEnabled: false\n # -- To enable the usage of embedded rego policies, set the flag useEmbeddedRegoPolicies. This should serve as a fallback for air-gapped environments.\n # When useEmbeddedRegoPolicies is set to true, useBuiltinRegoPolicies should be set to false.\n useEmbeddedRegoPolicies: \"true\"\n\n # -- The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner\n #\n supportedConfigAuditKinds: \"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota\"\n\n # -- command. One of `image`, `filesystem` or `rootfs` scanning, depending on the target type required for the scan.\n # For 'filesystem' and `rootfs` scanning, ensure that the `trivyOperator.scanJobPodTemplateContainerSecurityContext` is configured\n # to run as the root user (runAsUser = 0).\n command: image\n # -- imageScanCacheDir the flag to set custom path for trivy image scan `cache-dir` parameter.\n # Only applicable in image scan mode.\n imageScanCacheDir: \"/tmp/trivy/.cache\"\n # -- filesystemScanCacheDir the flag to set custom path for trivy filesystem scan `cache-dir` parameter.\n # Only applicable in filesystem scan mode.\n filesystemScanCacheDir: \"/var/trivyoperator/trivy-db\"\n # -- serverUser this param is the server user to be used to download db from private registry\n serverUser: \"\"\n # -- serverPassword this param is the server user to be used to download db from private registry\n serverPassword: \"\"\n # -- serverServiceName this param is the server service name to be used in cluster\n serverServiceName: \"trivy-service\"\n # -- debug One of `true` or `false`. Enables debug mode.\n debug: false\n\n server:\n # -- resources set trivy-server resource\n resources:\n requests:\n cpu: 200m\n memory: 512Mi\n # ephemeral-storage: \"2Gi\"\n limits:\n cpu: 1\n memory: 1Gi\n # ephemeral-storage: \"2Gi\"\n\n # -- podSecurityContext set trivy-server podSecurityContext\n podSecurityContext:\n runAsUser: 65534\n runAsNonRoot: true\n fsGroup: 65534\n\n # -- securityContext set trivy-server securityContext\n securityContext:\n privileged: false\n readOnlyRootFilesystem: true\n\n # -- the number of replicas of the trivy-server\n replicas: 1\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply TRIVY_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply TRIVY_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\ncompliance:\n # -- failEntriesLimit the flag to limit the number of fail entries per control check in the cluster compliance detail report\n # this limit is for preventing the report from being too large per control checks\n failEntriesLimit: 10\n # -- reportType this flag control the type of report generated (summary or all)\n reportType: all\n # -- cron this flag control the cron interval for compliance report generation\n cron: 0 */6 * * *\n # -- specs is a list of compliance specs to be used by the cluster compliance scanner\n # - k8s-cis-1.23\n # - k8s-nsa-1.0\n # - k8s-pss-baseline-0.1\n # - k8s-pss-restricted-0.1\n # - eks-cis-1.4\n # - rke2-cis-1.24\n specs:\n - k8s-cis-1.23\n - k8s-nsa-1.0\n - k8s-pss-baseline-0.1\n - k8s-pss-restricted-0.1\n\nrbac:\n create: true\nserviceAccount:\n # -- Specifies whether a service account should be created.\n create: true\n annotations: {}\n # -- name specifies the name of the k8s Service Account. If not set and create is\n # true, a name is generated using the fullname template.\n name: \"\"\n\n# -- podAnnotations annotations added to the operator's pod\npodAnnotations:\n prometheus.deckhouse.io/port: \"8080\"\n\npodSecurityContext: {}\n# fsGroup: 2000\n\n# -- securityContext security context\nsecurityContext:\n privileged: false\n allowPrivilegeEscalation: false\n readOnlyRootFilesystem: true\n capabilities:\n drop:\n - ALL\n\nvolumeMounts:\n# do not remove , required for policies bundle\n- mountPath: /tmp\n name: cache-policies\n readOnly: false\n\nvolumes:\n# do not remove , required for policies bundle\n- name: cache-policies\n emptyDir: {}\n\nresources: {}\n# -- We usually recommend not to specify default resources and to leave this as a conscious\n# choice for the user. This also increases chances charts run on environments with little\n# resources, such as Minikube. If you do want to specify resources, uncomment the following\n# lines, adjust them as necessary, and remove the curly braces after 'resources:'.\n# limits:\n# cpu: 100m\n# memory: 128Mi\n# requests:\n# cpu: 100m\n# memory: 128Mi\n\n# -- nodeSelector set the operator nodeSelector\n#nodeSelector: {}\n\nnodeSelector:\n node-role.k8s.lmru.tech/application: ''\n\n# -- tolerations set the operator tolerations\ntolerations: []\n\n# -- affinity set the operator affinity\naffinity: {}\n\n# -- priorityClassName set the operator priorityClassName\npriorityClassName: \"\"\n\n# -- automountServiceAccountToken the flag to enable automount for service account token\nautomountServiceAccountToken: true\n\npoliciesBundle:\n # -- registry of the policies bundle\n registry: mirror.gcr.io\n # -- repository of the policies bundle\n repository: aquasec/trivy-checks\n # -- tag version of the policies bundle\n tag: 1\n # -- registryUser is the user for the registry\n registryUser: ~\n # -- registryPassword is the password for the registry\n registryPassword: ~\n # -- existingSecret if a secret containing registry credentials that have been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: policies.bundle.oci.user, policies.bundle.oci.password\n # Overrides policiesBundle.registryUser, policiesBundle.registryPassword values.\n # Note: The secret has to be named \"trivy-operator\".\n existingSecret: false\n # -- insecure is the flag to enable insecure connection to the policy bundle registry\n insecure: false\n\nnodeCollector:\n # -- useNodeSelector determine if to use nodeSelector (by auto detecting node name) with node-collector scan job\n useNodeSelector: false\n # -- registry of the node-collector image\n registry: docker-security.art.lmru.tech\n # -- repository of the node-collector image\n repository: aquasec/node-collector\n # -- tag version of the node-collector image\n tag: 0.3.1\n # -- imagePullSecret is the secret name to be used when pulling node-collector image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n # -- excludeNodes comma-separated node labels that the node-collector job should exclude from scanning (example kubernetes.io/arch=arm64,team=dev)\n excludeNodes: # -- tolerations to be applied to the node-collector so that they can run on nodes with matching taints\n\n tolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- node-collector pod volume mounts definition for collecting config files information\n volumeMounts:\n - name: var-lib-etcd\n mountPath: /var/lib/etcd\n readOnly: true\n - name: var-lib-kubelet\n mountPath: /var/lib/kubelet\n readOnly: true\n - name: var-lib-kube-scheduler\n mountPath: /var/lib/kube-scheduler\n readOnly: true\n - name: var-lib-kube-controller-manager\n mountPath: /var/lib/kube-controller-manager\n readOnly: true\n - name: etc-systemd\n mountPath: /etc/systemd\n readOnly: true\n - name: lib-systemd\n mountPath: /lib/systemd/\n readOnly: true\n - name: etc-kubernetes\n mountPath: /etc/kubernetes\n readOnly: true\n - name: etc-cni-netd\n mountPath: /etc/cni/net.d/\n readOnly: true\n # -- node-collector pod volumes definition for collecting config files information\n volumes:\n - name: var-lib-etcd\n hostPath:\n path: /var/lib/etcd\n - name: var-lib-kubelet\n hostPath:\n path: /var/lib/kubelet\n - name: var-lib-kube-scheduler\n hostPath:\n path: /var/lib/kube-scheduler\n - name: var-lib-kube-controller-manager\n hostPath:\n path: /var/lib/kube-controller-manager\n - name: etc-systemd\n hostPath:\n path: /etc/systemd\n - name: lib-systemd\n hostPath:\n path: /lib/systemd\n - name: etc-kubernetes\n hostPath:\n path: /etc/kubernetes\n - name: etc-cni-netd\n hostPath:\n path: /etc/cni/net.d/\n", "firstEditBubbleId": "4ba51dd2-26c6-43df-b0c3-0041b1347745", "isNewlyCreated": false, "newlyCreatedFolders": [] }, "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/templates/collector/configmap.yaml": { "content": "{{- if .Values.reportMetrics.enabled }}\napiVersion: v1\nkind: ConfigMap\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\ndata:\n custom-resource-state.yaml: |\n kind: CustomResourceStateMetrics\n spec:\n resources:\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterComplianceReport\n metricNamePrefix: trivy_cluster_compliance\n labelsFromPath:\n name: [metadata, name]\n benchmark: [spec, compliance, title]\n benchmark_id: [spec, compliance, id]\n benchmark_type: [spec, compliance, type]\n benchmark_version: [spec, compliance, version]\n metrics:\n - name: pass_count\n help: Passed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, passCount]\n - name: fail_count\n help: Failed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, failCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - name: control_fail_total\n help: Failed checks per compliance control from Trivy ClusterComplianceReport summaryReport.\n each:\n type: Gauge\n gauge:\n path: [status, summaryReport, controlCheck]\n labelsFromPath:\n control_id: [id]\n control_name: [name]\n control_severity: [severity]\n valueFrom: [totalFail]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ConfigAuditReport\n metricNamePrefix: trivy_config_audit\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterConfigAuditReport\n metricNamePrefix: trivy_cluster_config_audit\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: InfraAssessmentReport\n metricNamePrefix: trivy_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterInfraAssessmentReport\n metricNamePrefix: trivy_cluster_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: VulnerabilityReport\n metricNamePrefix: trivy_vulnerability\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy VulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterVulnerabilityReport\n metricNamePrefix: trivy_cluster_vulnerability\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterVulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: RbacAssessmentReport\n metricNamePrefix: trivy_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy RbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterRbacAssessmentReport\n metricNamePrefix: trivy_cluster_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterRbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ExposedSecretReport\n metricNamePrefix: trivy_exposed_secret\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ExposedSecretReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: SbomReport\n metricNamePrefix: trivy_sbom\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy SbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterSbomReport\n metricNamePrefix: trivy_cluster_sbom\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterSbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n{{- end }}\n", "firstEditBubbleId": "7aa728d5-677b-4e40-a8c6-0973c07e8b73", "isNewlyCreated": false, "newlyCreatedFolders": [] }, "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/templates/collector/deployment.yaml": { "content": "{{- if .Values.reportMetrics.enabled }}\n{{- $registry := include \"global.imageRegistry\" . | default .Values.reportMetrics.image.registry }}\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\nspec:\n replicas: 1\n selector:\n matchLabels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 6 }}\n template:\n metadata:\n labels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 8 }}\n {{- with .Values.reportMetrics.podLabels }}\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.reportMetrics.podAnnotations }}\n annotations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n spec:\n serviceAccountName: {{ include \"trivy-operator.reportMetricsServiceAccountName\" . }}\n automountServiceAccountToken: true\n {{- with .Values.image.pullSecrets }}\n imagePullSecrets:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n securityContext:\n {{- toYaml .Values.podSecurityContext | nindent 8 }}\n containers:\n - name: kube-state-metrics\n image: \"{{ $registry }}/{{ .Values.reportMetrics.image.repository }}:{{ .Values.reportMetrics.image.tag }}\"\n imagePullPolicy: {{ .Values.reportMetrics.image.pullPolicy }}\n args:\n - --custom-resource-state-only=true\n - --use-apiserver-cache\n - --custom-resource-state-config-file=/etc/kube-state-metrics/custom-resource-state.yaml\n - --port={{ .Values.reportMetrics.service.port }}\n - --telemetry-port=8081\n ports:\n - name: metrics\n containerPort: {{ .Values.reportMetrics.service.port }}\n protocol: TCP\n - name: telemetry\n containerPort: 8081\n protocol: TCP\n livenessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 10\n readinessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 5\n resources:\n {{- toYaml .Values.reportMetrics.resources | nindent 12 }}\n securityContext:\n {{- toYaml .Values.securityContext | nindent 12 }}\n volumeMounts:\n - name: custom-resource-state\n mountPath: /etc/kube-state-metrics\n readOnly: true\n volumes:\n - name: custom-resource-state\n configMap:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n {{- with .Values.nodeSelector }}\n nodeSelector:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.affinity }}\n affinity:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.tolerations }}\n tolerations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n priorityClassName: {{ .Values.priorityClassName | quote }}\n{{- end }}\n", "firstEditBubbleId": "08cfd30c-f9b4-4c39-b10a-bed5ddb11903", "isNewlyCreated": false, "newlyCreatedFolders": [] }, "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/templates/collector/configmap.yaml": { "content": "{{- if .Values.reportMetrics.enabled }}\napiVersion: v1\nkind: ConfigMap\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\ndata:\n custom-resource-state.yaml: |\n kind: CustomResourceStateMetrics\n spec:\n resources:\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterComplianceReport\n metricNamePrefix: trivy_cluster_compliance\n labelsFromPath:\n name: [metadata, name]\n benchmark: [spec, compliance, title]\n benchmark_id: [spec, compliance, id]\n benchmark_type: [spec, compliance, type]\n benchmark_version: [spec, compliance, version]\n metrics:\n - name: pass_count\n help: Passed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, passCount]\n - name: fail_count\n help: Failed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, failCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - name: control_fail_total\n help: Failed checks per compliance control from Trivy ClusterComplianceReport summaryReport.\n each:\n type: Gauge\n gauge:\n path: [status, summaryReport, controlCheck]\n labelsFromPath:\n control_id: [id]\n control_name: [name]\n control_severity: [severity]\n valueFrom: [totalFail]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ConfigAuditReport\n metricNamePrefix: trivy_config_audit\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterConfigAuditReport\n metricNamePrefix: trivy_cluster_config_audit\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: InfraAssessmentReport\n metricNamePrefix: trivy_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterInfraAssessmentReport\n metricNamePrefix: trivy_cluster_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: VulnerabilityReport\n metricNamePrefix: trivy_vulnerability\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy VulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterVulnerabilityReport\n metricNamePrefix: trivy_cluster_vulnerability\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterVulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: RbacAssessmentReport\n metricNamePrefix: trivy_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy RbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterRbacAssessmentReport\n metricNamePrefix: trivy_cluster_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterRbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ExposedSecretReport\n metricNamePrefix: trivy_exposed_secret\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ExposedSecretReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: SbomReport\n metricNamePrefix: trivy_sbom\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy SbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterSbomReport\n metricNamePrefix: trivy_cluster_sbom\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterSbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n{{- end }}\n", "firstEditBubbleId": "5ef06089-fe42-4f12-8319-8052af5eb445", "isNewlyCreated": false, "newlyCreatedFolders": [] }, "file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/templates/collector/deployment.yaml": { "content": "{{- if .Values.reportMetrics.enabled }}\n{{- $registry := include \"global.imageRegistry\" . | default .Values.reportMetrics.image.registry }}\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\nspec:\n replicas: 1\n selector:\n matchLabels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 6 }}\n template:\n metadata:\n labels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 8 }}\n {{- with .Values.reportMetrics.podLabels }}\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.reportMetrics.podAnnotations }}\n annotations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n spec:\n serviceAccountName: {{ include \"trivy-operator.reportMetricsServiceAccountName\" . }}\n automountServiceAccountToken: true\n {{- with .Values.image.pullSecrets }}\n imagePullSecrets:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n securityContext:\n {{- toYaml .Values.podSecurityContext | nindent 8 }}\n containers:\n - name: kube-state-metrics\n image: \"{{ $registry }}/{{ .Values.reportMetrics.image.repository }}:{{ .Values.reportMetrics.image.tag }}\"\n imagePullPolicy: {{ .Values.reportMetrics.image.pullPolicy }}\n args:\n - --custom-resource-state-only=true\n - --use-apiserver-cache\n - --custom-resource-state-config-file=/etc/kube-state-metrics/custom-resource-state.yaml\n - --port={{ .Values.reportMetrics.service.port }}\n - --telemetry-port=8081\n ports:\n - name: metrics\n containerPort: {{ .Values.reportMetrics.service.port }}\n protocol: TCP\n - name: telemetry\n containerPort: 8081\n protocol: TCP\n livenessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 10\n readinessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 5\n resources:\n {{- toYaml .Values.reportMetrics.resources | nindent 12 }}\n securityContext:\n {{- toYaml .Values.securityContext | nindent 12 }}\n volumeMounts:\n - name: custom-resource-state\n mountPath: /etc/kube-state-metrics\n readOnly: true\n volumes:\n - name: custom-resource-state\n configMap:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n {{- with .Values.nodeSelector }}\n nodeSelector:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.affinity }}\n affinity:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.tolerations }}\n tolerations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n priorityClassName: {{ .Values.priorityClassName | quote }}\n{{- end }}\n", "firstEditBubbleId": "6448a3c1-9c6d-48d4-abe1-72a197c85fc0", "isNewlyCreated": false, "newlyCreatedFolders": [] } }, "newlyCreatedFiles": [], "newlyCreatedFolders": [], "lastUpdatedAt": 1773313861707, "createdAt": 1773308045531, "hasChangedContext": true, "activeTabsShouldBeReactive": true, "capabilities": [ { "type": 30, "data": {} }, { "type": 15, "data": { "bubbleDataMap": "{}" } }, { "type": 22, "data": {} }, { "type": 18, "data": {} }, { "type": 19, "data": {} }, { "type": 33, "data": {} }, { "type": 32, "data": {} }, { "type": 23, "data": {} }, { "type": 16, "data": {} }, { "type": 24, "data": {} }, { "type": 21, "data": {} }, { "type": 31, "data": {} }, { "type": 29, "data": {} } ], "name": "Reading reports with filters", "isFileListExpanded": false, "browserChipManuallyDisabled": false, "browserChipManuallyEnabled": false, "unifiedMode": "agent", "forceMode": "edit", "usageData": {}, "contextUsagePercent": 84.74779411764706, "contextTokensUsed": 230514, "contextTokenLimit": 272000, "allAttachedFileCodeChunksUris": [], "modelConfig": { "modelName": "premium", "maxMode": false }, "subComposerIds": [], "subagentComposerIds": [], "capabilityContexts": [], "todos": [], "isQueueExpanded": true, "hasUnreadMessages": false, "gitHubPromptDismissed": false, "totalLinesAdded": 954, "totalLinesRemoved": 736, "addedFiles": 0, "removedFiles": 0, "isDraft": false, "isCreatingWorktree": false, "isApplyingWorktree": false, "isUndoingWorktree": false, "applied": false, "pendingCreateWorktree": false, "worktreeStartedReadOnly": false, "isBestOfNSubcomposer": false, "isBestOfNParent": false, "bestOfNJudgeWinner": false, "isSpec": false, "isProject": false, "isSpecSubagentDone": false, "isContinuationInProgress": false, "stopHookLoopCount": 0, "committedToBranch": "DSO-102", "createdOnBranch": "DSO-102", "activeBranch": { "branchName": "DSO-102", "lastInteractionAt": 1773313745533 }, "branches": [ { "branchName": "DSO-102", "lastInteractionAt": 1773313745533 } ], "speculativeSummarizationEncryptionKey": "Hr4qakxdBHW0C5jQmg8qhUobhg6EQrV3Zd2OcDdtVaM=", "isNAL": true, "agentBackend": "cursor-agent", "planModeSuggestionUsed": false, "debugModeSuggestionUsed": false, "conversationState": "~CiDcNtNS/ttQPMUZhGkpqcqK0asra1BEUTyHkyWuovHEjwogHwywSrX93rRsMBFdJGjP7rjf2xpZDciEMVgSXRaxbOMKIEjrVSm9P7RCu1vc+xIm5lNTmggdDOczcZe2zyaHDnRqCiAEsZy84fg/owbGxQNknoRuwr4HW8VvtH9xVYWWt3/LWQoggYbrQenPy4pY7//zzuKoAsrpMyZof4Dl0oPM/x89FgQKINgTZu3JXJTz52tivD83AVyntWm1+1gbhkL2JqjlOs3fCiCnVdpZh+3v/fh3iAaCwitiihETO2/9qzAx26SDXXaTcAog+Jql55xI245aaPwcLgjnMF2om4U8PYOWeAUCnxFbKVkKIPuyKDif2EuHaTeyi+uhiO2woKedGY6bcDVvTyL8FrOhCiA+BrblfoFOtqTT8qOSNQ47MyDltlEAFmfTegzYGowSGgogp+2oqD+wxqSGWL8nbqamW12Radqt9+VDsuzaGKdZkBEKIPSG/LXjfOqSRy4rd+9j5obtoH5VN7JpV85IJ4ETbh7UCiBEe8ZN25U4tmxHCvs1Sz9Tky6q3GehjN1aY35Pdl9QewogdDnNUhMmV75Z7Q+lYAbk+zZoNyJvOS7bbAKmCUYWzA8KIM6ayiySGBYg9zE4FHi2MiUxA4/Xwh7vXyB//mAToeR7CiAfdxRKhZWJ7C35AWITsiP6gCYGwvI/P1yRkkp/vrc9BgogYlbQ70d3/g7Qp7Van2clwfwNKF8alycCND0smePnZ/gKIPCfX4e8f2GjCNNIm/p99qByr3hAxSHp0M7/M7LZxD/mCiBMbCJ0lofqnsGWA7rb+U4XdN61KMM9uveLN1YOcPr4SAog06aXsS2TVEOuV1H6zutYra0uGVhOdvyhE8b/pTRYH7oKIM4Ufiv9EjAbrCZLoAJidD7gDDroo9SNFS6HGBijQ3QLCiBaYwfj5MsCYAsVrHpv963kdK4GpvxLhM1QQISg8e/2LQog/TIu7OFAlLgGqfAa1NiKdyNTreoVmpMrY7ApyCbKE5YKIEtruDyumLAsekV09VWEGsaUaiiLnR5mFwhUFMP3Ke3ECiDerPpZIpSkwTlIAF7CUG0TzEdqPMw4knbLpNaXec0g2wogKePORsiuDl48VSsJ5H38dXPuADRcbBpy1MJAydEKfeMKIFKL57WF54ZSJhcw08PnnnkBtpEVm6neTbbNzMPcRkt2CiC2sCiuPEDOnR2xOxNgWtfFPFyawkYS3ugIwiJlEMZD0gogdxjWcdfcH3n2mi6o7axAhKoXdX0L0lGwP41CkDVJD5QKIBD6BQil+qEs6lLv8LFUqpM8Zfny5+LFHWrvrpQxO1KQCiCCbKnBO/69BDwRTP8vHPolyBZJpcmeEs98szfZFLgFgwogxyjdrUL2MvSadEycJGDvn1TkDJPoW2WHnLoQSEEnUHwKIFvikxlJIKYwNqY1cJw8Mw0Lxyg+6rN8FoaggH0F50k5CiA1UVC95fI1VpsM7QeMYDth65p8E3C8K2FFgWltpl+18gogXdM5JeZTc0oEsfefBUjkNIRNMIzlCGt/zHnnVIo0F/QKILRDR3vxq6vdLr/B/Tg94crr9EhdFJMLBgfbZ8fVjPTZCiDCUj9DpSI63bMJIux/iW4vbeu+4y/7tlWgDXlHXYvOTwogACPuUDjzG8tTgZqd8kxtRGiiLtf3kbvR0yAKtehvnEIKIKH9jan3/zSs1PMYRXY7dEl1xIrokRqgwMDU6jVMvwXUCiA0k6m3IqH4+jWI1nyv10RHgTDiI3vLhMiv6Qt+kDKbHAoghM3tEY70bifl2GNClsCjo2UvxQ5jHlrgDd6k8W3erxoKIIl20TN55DiSbCB3OouIl+GbpSrFHzxy9R/2XbzozBshCiDGJGXPJEFRxeZvK/5jdThVC1AIN4XrBspSJ4mZaaCfIgog9Pegw/lnIZ+X6+apO5QPBdnd/iCKswwfSBxcqMG45bMKIK4hCPkd1k0WN2fL16VeoyrmIbiwStHoGuVxyotnovpwCiCUWAQN5AYrw3GaCBia+M5r4T7AGuc9XLns7AT0o20Z4gog9BtvVMYTrK+k93odlOa2z5GRGpup6CEtVW6fOWA4bA8KIB7BMMGMtKVHlfMRiZ3p28j641rFDlOJQmTrJNeHGKLFCiCLu+Kti2mdhp6Bjfx/6fshpju/BsRbkkE2Jgx8XvhN0gogUylqgYf41ZLtVr4Anm5i+AlmptLz+vMwUPG0l9cVajgKII3txQ6a3AFvCJOo537pyhO+60IWoZbNi9liNw2dIyxxCiCfD4T3X80fi1EOr0dgR7ZF/23So40m1+ZvIpRpcw6iYAogsY3up9X+yMkvUPYXm9lQwDyLvo4jobBasITL1kmkX0QKIEdWJ4HuHephZlUSRWX8Q2J0s8r+L5NZ7g6jDRJk7QhGCiA9yaXWhETXVZWnUWs7Ts0/izn2VRJ4tAqRalon0566GAogHHQtzhBERlqa6RH6n+O+s3XKu25WGyFTrIxhH0Zd1YsKIKr8NK7JaOvtznWVGh08rJK8LyD/dqu+ZkeSTCu6+BbDCiADDA+mUzZDiEDMLlWv8RWoGfktwHgMrvChL4QtAE08TQogTLc+54ZxTxVkGdiziQRQ0RmrKoT7/4mItQY53r1Y6VYKICXnu7bTVqCB1A7nxHA3nJcIG1UG+Ap0yNqvRlac53wmCiDd/fVBJB9tjoKMGH03StIiFikwMlztDre2h8KG0hpcSQogYSXs77ABqeOEZkg3cU7uKt9axlhXywgdpMROM1zJjCUKIHi4DefWsPaFm0yuhTAsr4N35ARXCdkuYTzbhhp94MisCiAQjXFDMb6ou2o9ZxHyH1IYIhZ81iQgVPpPQ2OKKUxMWgog9GYkLnCeaOrm8t7Dzy8PNADzhTR14l/0TbDEAzwt23IKINxoyUkw/ecGaHMSKlzKm+ul5Qbih94aUrRqjmdz9xaDCiDnJoY38F/F3AHVOzJ4V5twyvVFhR4T4CbEgHTlMFH6MAogPTAedioC3+Xt0M35njIbgUakVXsKziz6kcCF0KWHpvsKIBYX2OFMFUkVsOX+653Z6B1Zsh0TuCfNYBaKGYtNce5+CiB/sMXmzS6G4h46xyTJk4/FRDlDcpTKVkshCZ6FGrN+cQogdBDxQlxDvxYgROBALEA84UEqIjmmdQP1CZhKMCd9dGoKICokc+hkJ+tqMw2xpmvtNUZY/4DuqOAnmErxgpAy2pFuCiBuBfBtUckza4HjGv3tOop/pXJvuVI1mDQtM6MrZuBxAAogmJL/w+T+5rTfLLTJDkD9IRVu/D5rhWziPuqNG4RJlggKIIgTwjJUvUHW9RZE4+XpgjbfTKRoLt/dShMyWaP7BKqCCiC2Aq/Dboa3Ne7oxmRZ8owTshJeLdjpOYKu6bGxJLRrAAogxDtTXRhJEUsqNAX61BozDvFJ6lmYfBIqvmsm0TzHcRgKIHz84b8JAe8sx2XqonU6e/KL0zrc3TkryhGfnXt3NBiVCiCz3EWw6kGZhrKopZg/gah4awQCxfH/Y9fVXaTUQKWCUAogIbGOizoHt/9bvXUhun78eZ3sidNvCMGEpKfGo8Y8Xu0KIMyaRNNTxwkmantTkwZT03ZDBTm1k2xUbp8j1n9/kMcZCiBRHZgX//4LsEH9zIyYAqIXNUZw+g6tWaxqf8LCvWoGGQogDPSeDOq2QI+LRjKmbUeBUumP2o5EzZSFPTvlQKAYMIkKIOhcEZ83y1N7LQEdchVtBZJaKREZAUXKNADqu3BqXnMfCiABlI+NnkG2Fa5ZYAwhnE4SQLjMX+B8iBucju7mp+7joAogY1SavHdD3q2hdVz1B7UIDdzUx2SYdiCBckSKh26wVwAKIBBAkmCf+D1dhVenF0RsdpJVP8NVQnks4S96kYGVB5DbCiAec/kR4F/J6p4r2/113oQizXQuQYsIwTLVFugONafDewogb6/cYj1TRicp5ygg1/3v9NDwoi4dFJy06vBPuzrZ9iEKIBUt7JqZSDZvDFByEVUtlCn2jgVoybCVTfWZKmWwP4POCiBxS+5/5vf8KCqsT7ZFeqnuuIBIIjEZJQHKn2CH4yop9gog30Ih2CtIJekWMmxdta0gLHKPk48eYq3m0mMYliWkTwIKID0UCcSPA1LWQkqHv8oa+6/qOnQj0HxVcCSPfZrEeF6TCiDYKDoTdQUQwyI8lZB4/K4d1biZdqzCKQbfvkKzzPUJdQog8rv+isiqiLyESY9Io+1DOUazhbgA0vqjN3enpGgmYv4KIMT4eGSdx4UPhqBgxNwcj/9/xhqjWFDvsPayohjvJPhDCiCs/nNpciCDW9FbUNtah5GKSQ1Zz+/tcE33n1t6Wm7xlwogg9Ug59GPu+dkxWBmfcxCO/A4GKnPlnUZDwHkxH5SsoYKIIC2cicFAhe9vzUW+bgg+PIu7dt/D9dMhd0T/3jOa164CiC0t7uc18jUJnsoZGp4/t2QJKVN6jnisrO9LkYeRtKpeQogeZdU+6/RFOEQuJindl5/a/Lg2Y2Uq+u0NJzhR24pFAUKIOaD+rDA2LF8Vm2OJFYJ2G6x6VSXKKJsGJ06qsEvasnbCiCVHKrYJQzu8paDcIW4OYM6mDLeKCrj+0mdrer7jfW68gog0Auv8PiMcyIvZgQiSj/TzV2Ya9f1hpDhaw7IHfI45x8KIM5vlf9BBr/rwRj6gW74LEJv4W85KAPFSTrRjdUiBJSWCiAKyYArRTomc5pNTy3k8x+JeaNJyKEIqtuR0CT0bjs8DwogVp+c1Y8DwWtVIF4diBP/7xnihvYLpPpOmNiITvvlddAKINt5ek3ySCFGm3rhhArxA66jFcIB+4o+g+TJ0OqiCmn3CiB/zCbljDeq0vv8RBFIGZwInF4ejH3U707GtXJ2Qq/BBwogcU8dtwzUzLpCOhCd0QzvMnEVl0UTN228o8zwWX+BY+sKIOvIo2kFQDdlNBWLHJGp/IP/VVpCAT/tGSCI0BbeelwTCiA057IsKYW1VKLLKjlm3CiRgtON6uPVlv3AtfShy7tqzgogaxhL8Q9HYNBgwoUceCbwZjX80gJV6opuveyariUHNsIKICp1i5RoCjC49YMNEZY3dIX1J2WY9+g1em5+cKeW2L+dCiAjMafTpIVqRQTOlWkswIUm6bw15tHESCU0AphliGWg7gogRBffpo7osSFS6Gd8/bSUOj+hZgJWcohmsgTIOTkZoDcKICL8rEIma9QSldWWigqUeGprYS5aHi/jqW/1TMEgQp0LCiBMYOxnpJWyIAIHZeW7ePqKPZhc5nIXm8V2rpacHiw18Qog2EqhM3NTBQii7Uo/wkoHsAlPRr8TI1Cin7JoCcT5oswKINyOGcthONWZZefROhDMU+rJT0tITQBiDAjCrKjnmmfdCiAKlNYjJPWtkeeCphFPctqJNaq2ODE8izdOJJYjufd9NwogvlcnZTS+Tvx4677vm94MmNt1Zm+lriX0pyXkr/X9ee0KIIRqK560FvFv8A1mRslHMs1KWISZsmH8HB2ZEyJj8CT9CiCi+1jS1iKAbpIHKKBmhS0QY4RoSXaZRAq0ORHM07mUZgog09yx2x7f4gqJqslnX5k3kfuXjaSUfgQCk3yL/5QW7LEKIIJX0XMs9sKzUHoAjzHocgDectIhQw3dYcOCb9b304fpCiBy6mQpK/0ZPNWA1O0rrM/Saru1l2a4tctTdxgfm4Mmfwog6qCjo4JuuVHHRiy6O2D9AxRyIcB/qsS+nIxTHBI2wisKIKDBQ2HD336YMYp0CyG1INILlr4sfBojVUvFL+0+EE9OCiDYyQK7Z+6HVdWUcNEX0vUiHsFH/gRhvuMwBddHXSMA1wogyd9jo4j2pKUe20JtnKYgOG71HXnuhNYG0q441Hh2NZ0KILfMdos2+VE4rvrMAc2SQ8C/M/DHvtPyl9i4OM/Cz9xHCiB3ImwiHxcDBisXNiIZ0x7igwzxZtzw8ypnMGzQxbj3lQogh8EDGd45u+s9QE4JeoBeCvkU8m0aQ3AGSwub8dwKnBEKINjB6ur5aCVFWCk/mqbuIPfJwBhkVI7IOhmMDXk+1TgHCiBvb5xVqnLhshepMfsn1OXF8zYk5EcMc/trLjXpsbhAjQogLWrzbvXZyMvo54kSYdb7l4DjHC0Yv4MDzQ9+ck/bpgsKIOYR/KwmMKeo7brQn+10aO/hUU0VER/Zho2eIY1FUF8GCiDUCK3rIc2FH4tOBPWm2QUuVvlQWzfIunu42wnWCXVB3AogUyhG+o/k/1Artuqt014dObrdPlDXhDXEVbUxpv+aS78KIKt3KrRgMpfQqykVz64Mgzoa2NcqhI88hDSExxop2gakCiDQ0nbz0IShUwvfQnZgqgm71RQ+rY9VkxlRqclxcLlRegogIz7B8eIykeXsDxIyITt9jzehwgmc+5ibq0PegyuR2RUKIJoH03W2U0h1Gxw37IC0KYM7bmkL7EuhszOm2InwrVisCiAxqdWJQPHUo7yNcnX2chVJvLW/0e+J+jf3nzr66ikupgogj+vuXSSqocKRxR9GDMroYoT8fMrUCw+wbwW4OMXNY1IKIM2flyOWw2kcyIlh2TAG8NmlbyKk2Uwb4pX30rDbfjplCiDB0bOpj4AGJX6DAgwKOf+Ho/R+44pfumujWQ5jFMUVUwogTzBdBBVZKFuL1q+y9091HqxbhzPq7WJW5q/8JBRHChQKIB+Cm1xUQm0om1IZITaO8ClTwhtdE0AeprZCi3k2gkYFCiBt2aHkbV34XS4WadBftVdZGIIVXLMYWj9mvZbr2sxESAogbl2GHmdwAZCxMomhEGnQCCByTqEA8dnPdUx2nAIOLVQKIHMtdDWSdqe6SkkJ9vjerNnuRToFJKnXC6/7hDmuauJLCiAKV4VLhTR5kuMNZb2fC+O+/aDsgfy5+MaZTIDrAI6ycgogsHe6X8JdKBGx1DF2GOxCsTcMOvno/Oj5FVYWZcr41aYKIEu1b3gOI3lM5VRUxlgxvAfURXeV0ZDxW852uWFcLz7wCiC5IP6pyzup25QOdjjYGKFVrD4D69YTyF3Lx/C1hgerZAog7RClSbQNBxP7dDrQOLfQYxh0yQAt9txQ0As49ghbUJsKILek8WqvWzGQx7vRQ4Y5zD4wY+W+QmwDMO6ZB/WO2NyrCiCl6QYdjKSjy4wneYHN51aEnL3KKPouA5fbXmfRCS2iPAogCgw0IvvLdD3kABFqll4yfpF2lQQbXAfFtcYJi4Rya0cKIHwtBclVebQjvuW7l3fXHMG1lX6vjI5GNDoulTP2bJKTCiDMl9TWJwhTDg7H3eXz1UYF27mM0IRSV127ajQqT+eLPwogZC65VD5D3fgG0W2Oj3OrXu4xq4cwTwU1uAOJj6v9KA4KIGrZGiMHEKkDfnawATXSM/N75xOkAmpPvnkgDCf/6d1jCiDYG52PubqGq/XYX0nW8mfgJl0zO+ThG/2V4D1WdV4EkQogOL6ObrKk8qG4fzWiNqZ4bS8vBn25l0G1rt0TX/IMo/MKIAnDtVbNTwiQeW1oNswwXE/fJueJDXveCYimtYmyd5c5CiDJBPKe+AZQU1R5mE8lr2P5LZriVv6d2ACvDg96Zar3qQog9q+82DUbeq1bXdrpIbC38Q8OlqWzHzqrUlQh5EVPGaIKID8J4YCbytb0VYJ40LfTQv8ww/nnmGADdSel3tsVi6TuCiBUw82rlwP46ajfOOybRoMQhWFjh3cw5nf5rVryCzDtAwogO2axYGyNOZ6oJumgjVd6enlp7PMwGRpW4RttMXJiKyoKIFGhuj+wl+KmDoeFUUCQwdAJnrumPHq+dySt7PdO50+yCiC7WFTzgXDnxeIoEUAAfLChThy49LndeDvYRktd3IyIpQogfm6fkHbr7lnssZLeCDr8xWhuKUV+vhR/fuYtfdXL+loKICNY2Vz6AS58jj/4Sl7fiyir+HTtk0HQRohyEVtOw0q3CiDA46h45jt5FDKZZknQUdAOnA1UX6aYt7Dc+1ABq/5/fAogGwOgCI/LcQ9xtphvfvqrVgX4/bsj+KWSRqa7XgBkfs4KIOukRLi9jTIlt/LZhBrYvzLg+kH1IVDeB0W0x7plM/oMCiDjZwXFDSa5d/eusiasrt44n5XkeCz6XRuyW+RVgc+Jhwog2AmNPRJYBgKm051PQyPmmLa8miYqDgiJCdaZbZhgKN8KIOJ+/9qGlSr3R75jrN54JGmvguT1g/ZOYKt0JdTD4CIiCiC5mVu5o83c1JnFwQVdKeY3kNs9UGZ2Ao3mRIU/UwF9TQogXH7D7omK2XozEO5UQON2hWq2SOpfeCXuzos2vx/h9N4KIGaUqGcdAQcgNeBsd3R5+L68uCD8zJHQvV/zzmgKtWQsCiBRMFYj0HwwrCvGoJlH1pHi22usF6k3ldwLYyRUTKPzMgogADvNJutHZmFZwcKC1BY4y4lf1Q6/MjMvkeFMmVLmVyIKIIPRP5/vQLnzxy9aqLPemScnswaBP+eOsNLidFQOqfNIKggI8ogOEIDNEEIgF+F8SyNn3PDMaAS5Fn1tJXYkJKhJWAim9dNbR1N04f5CIFjBsGEkIpIrmV1SeQ1L8rAaPt08cOeGsxf24p6vVX1CQiApucbE+OoBqsyQt5pSk3oFujMmdz9ORoONONKuB7eagEIg+12eLdsX/5Db6G8rCXWzZewBXXJAAuLli6EB67x3tXlCIFOrDvEMXj+A3KH8+ypXoNXJxeU4MZWKYzOq/iTwvjidQiBL4WiahZChuKXigMpNY3LT1km06pXEDgApoIJQWr6tW0IgaQs6gh9rwv6u3ckcV2hrqpGqFjboHb83vlmjem4wHJVCIOCvUF+CG0p1Bt4t9FBDsacBea+9Rwd0VPHAsu2ZL5YhQiChfoWIjs7ToLbNA3dpc+Rs+0DpEGUCPOBV+crUFoA3OUIgCIKmbLQc+DSRKO2bVj7ECXKXCNGwZDj0dzdk6Cu8pidCIKro+AUJRi4Xb3BIQVkM+tNQcK0R9kDqS4P4q+uBrNyUQiCx00Dk4DA3j9C3Fh9C14IGmcyQjkMHmQcOZ0DWk+pUa0Ig8Rdv9ULUXj0Pfb/6WXnG5kfm+B7b0v9uvSVFv/W6PEdCIGA4iyMSopgxd+AtuaGYqHZZWx+S8fgggv5K40TR+i4cSj9maWxlOi8vL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHNQAXq/AQp3L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvdGVtcGxhdGVzL2NvbGxlY3Rvci9kZXBsb3ltZW50LnlhbWwSRAog9+eHV9ASNObuOjZq6Z5vyTSy1Zn99/WEfXgoDH3RY0USIEcFDDbZk887RKvplSKd5VGiRCPY8KFRcDlwwayvxj6nesABCngvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9kZXBsb3ltZW50LnlhbWwSRAog9+eHV9ASNObuOjZq6Z5vyTSy1Zn99/WEfXgoDH3RY0USIEcFDDbZk887RKvplSKd5VGiRCPY8KFRcDlwwayvxj6ner4BCnYvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC90ZW1wbGF0ZXMvY29sbGVjdG9yL2NvbmZpZ21hcC55YW1sEkQKIHEnyLV4Al2DBWeXxR68sPK5rYR0XBD1Q5I4BeL+eonxEiBsfY+vGEDATL8kDO7f2oRahvpxaLSPO4bEizsZiLvkEXq/AQp3L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9jb2xsZWN0b3IvY29uZmlnbWFwLnlhbWwSRAogcSfItXgCXYMFZ5fFHryw8rmthHRcEPVDkjgF4v56ifESIGx9j68YQMBMvyQM7t/ahFqG+nFotI87hsSLOxmIu+QRerUBCm0vaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC92YWx1ZXMvdmFsdWVzLWdsb2JhbC55YW1sEkQKILgDRkBPUXGB3feGQDhVa01nZsgfY1e2BZmnY+0S7vcjEiA89dWffLt7WL/HnolskwdHewhNvADHZh0zwQecB6WS2Hq2AQpuL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3ZhbHVlcy92YWx1ZXMtZ2xvYmFsLnlhbWwSRAoguANGQE9RcYHd94ZAOFVrTWdmyB9jV7YFmadj7RLu9yMSIDz11Z98u3tYv8eeiWyTB0d7CE28AMdmHTPBB5wHpZLYkgF4L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL2Rhc2hib2FyZHMvdHJpdnktY3JkLWRhc2hib2FyZC5qc29ukgFlL2hvbWUvcnVzbGFucGkvLmN1cnNvci9wcm9qZWN0cy9ob21lLXJ1c2xhbnBpLURvY3VtZW50cy1yZXBvcy1sbXJ1LWRldm9wcy1hcmdvY2QtYXBwcy90ZXJtaW5hbHMvMS50eHSSAYABL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvZGFzaGJvYXJkcy90cml2eS1jcmQtZXhwbG9yZXItZGFzaGJvYXJkLmpzb26SAXkvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2dyYWZhbmEtY3JkLWRhc2hib2FyZC55YW1skgF4L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvdGVtcGxhdGVzL2dyYWZhbmEtY3JkLWRhc2hib2FyZC55YW1skgGBAS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS9kYXNoYm9hcmRzL3RyaXZ5LWNyZC1leHBsb3Jlci1kYXNoYm9hcmQuanNvbpIBdy9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL2NvbmZpZ21hcC55YW1skgFuL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3ZhbHVlcy92YWx1ZXMtZ2xvYmFsLnlhbWySAY4BL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL2NyZHMvYXF1YXNlY3VyaXR5LmdpdGh1Yi5pb19jbHVzdGVyY29tcGxpYW5jZXJlcG9ydHMueWFtbJIBigEvaG9tZS9ydXNsYW5waS8uY3Vyc29yL3Byb2plY3RzL2hvbWUtcnVzbGFucGktRG9jdW1lbnRzLXJlcG9zLWxtcnUtZGV2b3BzLWFyZ29jZC1hcHBzL2FnZW50LXRvb2xzL2IzYjgzNTk3LWI5MjgtNDdkOS1iMzM5LTM1MzA2ZGU5MGYyMi50eHSSAXkvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9jbHVzdGVycm9sZS55YW1skgF8L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9jb2xsZWN0b3Ivc2VydmljZWFjY291bnQueWFtbJIBeC9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL2RlcGxveW1lbnQueWFtbJIBgAEvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9jbHVzdGVycm9sZWJpbmRpbmcueWFtbJIBdS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL3NlcnZpY2UueWFtbJIBdy9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29uZmlnbWFwcy9vcGVyYXRvci55YW1skgGEAS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29uZmlnbWFwcy90cml2eS1vcGVyYXRvci1jb25maWcueWFtbJIBdi9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvc3BlY3MvazhzLWNpcy0xLjIzLnlhbWySAYoBL2hvbWUvcnVzbGFucGkvLmN1cnNvci9wcm9qZWN0cy9ob21lLXJ1c2xhbnBpLURvY3VtZW50cy1yZXBvcy1sbXJ1LWRldm9wcy1hcmdvY2QtYXBwcy9hZ2VudC10b29scy81MTZiYjdlOC1jZjUwLTQ2N2MtOWY4NC04MjZjNDdmNWMwYTkudHh0kgFrL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9faGVscGVycy50cGySAWovaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC90ZW1wbGF0ZXMvX2hlbHBlcnMudHBs", "queueItems": [], "blobEncryptionKey": "ijf0mMgGI2Ar2LUlMY1QE0wmSfaq4VtoVhl/SH1geIQ=", "latestChatGenerationUUID": "c8230c77-a958-4a9c-b5ec-4159eb2b4ab1", "isAgentic": true, "subtitle": "Edited deployment.yaml, deployment.yaml, values-global.yaml, configmap.yaml, values-global.yaml", "filesChangedCount": 6 }