Files
Ruslan PiatrovichandCursor 532ac723cb Add full Cursor chat archive for Documents/repos workspaces.
Includes global state.vscdb, per-repo transcripts, workspace storage,
composer exports, and restore scripts for a new machine.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 11:53:07 +03:00

1076 lines
143 KiB
JSON
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"_v": 14,
"composerId": "e934b96e-a11d-4ebc-8f59-1cb2ebc8cc34",
"richText": "{\"root\":{\"children\":[{\"children\":[],\"format\":\"\",\"indent\":0,\"type\":\"paragraph\",\"version\":1}],\"format\":\"\",\"indent\":0,\"type\":\"root\",\"version\":1}}",
"hasLoaded": true,
"text": "",
"fullConversationHeadersOnly": [
{
"bubbleId": "2f4fbaa1-93ee-4533-8149-54c667ca32cc",
"type": 1
},
{
"bubbleId": "a27bdfe1-19ab-487d-8139-4d0777e99d7a",
"type": 2
},
{
"bubbleId": "fd570486-b204-449f-b2e9-0c34b46db5e8",
"type": 2
},
{
"bubbleId": "591af5bc-a116-4ca4-9490-616f8db4d97e",
"type": 2
},
{
"bubbleId": "d1091f13-8a61-4de5-874d-fe80a59cf8a3",
"type": 2
},
{
"bubbleId": "ebd127de-4d81-437f-b2b3-5f7eef3647eb",
"type": 2
},
{
"bubbleId": "03538778-6d16-4f92-a290-72aee765a505",
"type": 2
},
{
"bubbleId": "13375ca8-e202-4472-8e94-567f0f3811f4",
"type": 2
},
{
"bubbleId": "42ca5327-e930-4847-85f9-c7bda77111de",
"type": 2
},
{
"bubbleId": "849a512a-2683-4320-abc8-d29c83e3bda6",
"type": 2
},
{
"bubbleId": "815a1b26-bda0-405c-99ac-fb110f1db07b",
"type": 2
},
{
"bubbleId": "ddd023da-2757-4b20-b21c-9fc6757775e2",
"type": 2
},
{
"bubbleId": "8ca471de-029c-4837-8ccf-32d43520c397",
"type": 2
},
{
"bubbleId": "d8bf7d1f-fb28-4a0c-9d22-0074f661c165",
"type": 2
},
{
"bubbleId": "ec5e9688-bd86-4a25-b05d-5c434d2bf67d",
"type": 2
},
{
"bubbleId": "2055eee8-adc5-4565-8259-120a64af7be8",
"type": 2
},
{
"bubbleId": "8f25cdf4-c6fe-4bfb-b0ce-52a8b3e65617",
"type": 2
},
{
"bubbleId": "cd1f464d-cd5c-4be7-81f9-d39afe93108b",
"type": 2
},
{
"bubbleId": "e8b720d5-04fe-4ec9-8857-a16d1a7335b1",
"type": 2
},
{
"bubbleId": "87a0b240-56db-48aa-986c-51adb66c5605",
"type": 2
},
{
"bubbleId": "dd52376d-aac0-4555-9578-dd1bf7bc1aba",
"type": 2
},
{
"bubbleId": "be993d16-09db-4a34-a5ab-81ff00217fa4",
"type": 2
},
{
"bubbleId": "a6cc19e2-dee2-4236-9ae5-37b3b58b4543",
"type": 2
},
{
"bubbleId": "61be342f-5c8e-4cbb-99a1-f94dab05fbdc",
"type": 2
},
{
"bubbleId": "9aa5f30b-b19b-4850-a7f8-478e95730ab2",
"type": 2
},
{
"bubbleId": "b2c1c313-3dbd-439a-8294-16ffc9ef0a8c",
"type": 2
},
{
"bubbleId": "2456164a-2c96-4ddf-bee3-5e5ca06067c4",
"type": 2
},
{
"bubbleId": "a54ff4dd-91b6-4cd2-ae59-135a5b8db18c",
"type": 2
},
{
"bubbleId": "8bc37dd6-5481-4861-a603-96f90c322310",
"type": 2
},
{
"bubbleId": "6d8d2a6a-23a4-4c9f-ba7d-c769f2652563",
"type": 2
},
{
"bubbleId": "388e42be-4c17-43ce-8c59-7d3604036983",
"type": 2
},
{
"bubbleId": "5ca05fa4-69f7-4403-9b3d-e6d5d10e338a",
"type": 2
},
{
"bubbleId": "9c4ff888-cafd-474f-b868-2b4a40e97239",
"type": 2
},
{
"bubbleId": "40186727-0a86-486c-b8ee-3f76ae4639ff",
"type": 2
},
{
"bubbleId": "1b07eeba-5959-4eaf-9aa2-f0588e836ca5",
"type": 2
},
{
"bubbleId": "ac5f644c-7c4b-4ce8-82bd-98705e4419f1",
"type": 2
},
{
"bubbleId": "b17bc3db-5335-4ebb-85a9-c8e49a706e0f",
"type": 2
},
{
"bubbleId": "7b669f1a-abfa-4e0c-acc0-b9bb03bac940",
"type": 2
},
{
"bubbleId": "d44bffb7-4463-42bd-9464-da02834520f4",
"type": 2
},
{
"bubbleId": "c53de2c0-8ff1-4aa6-a88e-176ca85b8be1",
"type": 1
},
{
"bubbleId": "66cb38aa-ecc6-4726-8a60-0c7fd03e1ce1",
"type": 2
},
{
"bubbleId": "457ec122-a0f7-4cfe-902e-75abd2ec8566",
"type": 2
},
{
"bubbleId": "cbaa0e0f-415f-437e-bc74-1cc1c49b6870",
"type": 2
},
{
"bubbleId": "5a7d9ba9-0611-41ae-be10-158681a30fd6",
"type": 2
},
{
"bubbleId": "39e4e1dc-3f6c-4069-a3c6-06e03e776048",
"type": 2
},
{
"bubbleId": "2f7843a9-d02e-4acb-856c-572a94e81137",
"type": 2
},
{
"bubbleId": "59e7530c-71b0-4d2a-98b2-e1f3f5c2308b",
"type": 2
},
{
"bubbleId": "167db4db-4cce-4781-9abc-51fe15cfbf7d",
"type": 2
},
{
"bubbleId": "ad925f07-4090-4dfc-ae56-dd5d49e2e758",
"type": 2
},
{
"bubbleId": "8d9f9ed4-4976-4efc-b7d0-33eac249ee10",
"type": 2
},
{
"bubbleId": "f568ab44-6993-4789-95f5-b16740d886d4",
"type": 2
},
{
"bubbleId": "47f2cf17-bc04-4f37-a2df-66d9a7e190b1",
"type": 2
},
{
"bubbleId": "68034c2d-f9f4-42c5-aaff-904c3815c4d0",
"type": 2
},
{
"bubbleId": "cc2cd0f0-b8db-4b73-8bda-a4047d724ade",
"type": 2
},
{
"bubbleId": "dc592989-5337-4e7f-a9ae-202212c3229c",
"type": 2
},
{
"bubbleId": "15aa8719-45d9-4add-9676-8994a7642fce",
"type": 2
},
{
"bubbleId": "69fc6973-2f75-4334-a5e0-d72787143a3c",
"type": 2
},
{
"bubbleId": "d53b77de-f74b-422a-b596-5cd468fd1f04",
"type": 2
},
{
"bubbleId": "24879b24-ecfa-463b-ad54-62e902bf486b",
"type": 2
},
{
"bubbleId": "643d5cf4-521d-4ffa-9d4a-947c1159aa6d",
"type": 2
},
{
"bubbleId": "f23b1a69-1cda-46f6-895e-05f26b7661c3",
"type": 2
},
{
"bubbleId": "271057e1-25d8-46a4-9200-4251b23a42e5",
"type": 2
},
{
"bubbleId": "05586fe9-93ba-4daa-9f96-fd96e68ade8d",
"type": 2
},
{
"bubbleId": "6e6ca964-abc4-4c66-a510-a4c4734e295e",
"type": 2
},
{
"bubbleId": "23254172-81fb-45fb-a686-7871555d8cbb",
"type": 2
},
{
"bubbleId": "7b68bca8-e6b8-4e1a-a189-55a2e08e476f",
"type": 2
},
{
"bubbleId": "b7d626fe-e9e6-4bbc-963e-dbde9de96a3e",
"type": 2
},
{
"bubbleId": "a4e781c8-82b7-4fdb-af81-9dbcb553f1b5",
"type": 2
},
{
"bubbleId": "59602b00-0108-4045-af33-c8caca42a4e3",
"type": 2
},
{
"bubbleId": "c8dc48f3-633a-40d0-a914-a39bc1ae091f",
"type": 2
},
{
"bubbleId": "a20b9465-4d26-4dc8-8405-302df05d9383",
"type": 2
},
{
"bubbleId": "421ee025-1a67-420d-8d00-b240abbf0b5a",
"type": 2
},
{
"bubbleId": "a818cefe-6c83-49e6-b15f-12687f7b3ed2",
"type": 2
},
{
"bubbleId": "3600f24e-e2f2-4b20-9c09-6cebf52d8467",
"type": 2
},
{
"bubbleId": "ac913b1d-c06a-4c6a-84d7-d06aff3cd1a8",
"type": 2
},
{
"bubbleId": "d9b44b6c-c335-45bd-a66b-e682a7ac27ba",
"type": 2
},
{
"bubbleId": "dd79204e-fb8e-4a6a-8e1f-0621c803017a",
"type": 2
},
{
"bubbleId": "9e84a332-392f-4b53-9670-9da986402e6c",
"type": 2
},
{
"bubbleId": "dacddb71-2c4d-41e2-9e99-ebd7b56933d3",
"type": 2
},
{
"bubbleId": "8d426d4a-d3b0-409f-889b-ef033feaa48b",
"type": 2
},
{
"bubbleId": "9f8f9e92-fded-4508-a96b-f24e7ae72b1b",
"type": 2
},
{
"bubbleId": "bd54577f-84eb-46cd-9426-b3a2abb26d43",
"type": 2
},
{
"bubbleId": "e60e07ea-feb8-47bf-8e9a-9bd5a090587c",
"type": 2
},
{
"bubbleId": "cc01c8da-bb5c-4dad-8084-d5829a1284f2",
"type": 2
},
{
"bubbleId": "859252c9-caaf-4bee-a180-ed24bc533ef0",
"type": 1
},
{
"bubbleId": "86562abe-bda0-43b4-b8d0-3c135438b60f",
"type": 2
},
{
"bubbleId": "4c1ac54a-c662-4e23-883f-1591c3652dd2",
"type": 2
},
{
"bubbleId": "3256a4bd-5a6d-45fe-a396-e00e97e84dfe",
"type": 1
},
{
"bubbleId": "c38e6712-9283-49b2-b786-29ebde71e7fd",
"type": 2
},
{
"bubbleId": "6ca198bf-b634-4d83-8176-398a65c8d816",
"type": 2
},
{
"bubbleId": "e70064c8-11aa-4115-9a33-7ca175a98a7d",
"type": 2
},
{
"bubbleId": "782b6224-53c8-4f85-b78d-eaeaa96ba10d",
"type": 2
},
{
"bubbleId": "7ba3099f-c7b9-49ae-8c41-999c2cdb3e92",
"type": 2
},
{
"bubbleId": "c8fb9ae1-f309-4e30-861a-dcc0864e56f0",
"type": 2
},
{
"bubbleId": "d6cf424a-8ca7-4629-a134-abade7c89eb9",
"type": 2
},
{
"bubbleId": "cfd2ce26-4f9d-4a18-995a-9e80763f497b",
"type": 2
},
{
"bubbleId": "475a0844-d1cb-4dad-b55a-e9b93c1e12ff",
"type": 1
},
{
"bubbleId": "d9833d34-1e58-4ae0-8492-95cc8c355607",
"type": 2
},
{
"bubbleId": "c98e277e-5070-4832-98b9-d4cc470c995b",
"type": 2
},
{
"bubbleId": "2be58e6f-d13e-4f5d-94ec-489f44248323",
"type": 1
},
{
"bubbleId": "5e03cd26-1d15-4e87-affa-19426d63c703",
"type": 2
},
{
"bubbleId": "51b81dec-b237-46ce-b99b-8a4672f9ec5b",
"type": 2
},
{
"bubbleId": "052fbce0-4c55-431b-b477-f75ca7c614b3",
"type": 2
},
{
"bubbleId": "66b1a8d7-4a7b-4a11-a313-db7e233e5d00",
"type": 2
},
{
"bubbleId": "39d05ebf-bca2-4869-957f-ff20e1cbdd26",
"type": 2
},
{
"bubbleId": "f5822428-f73d-44dc-82fd-d549351d874d",
"type": 2
},
{
"bubbleId": "4ba51dd2-26c6-43df-b0c3-0041b1347745",
"type": 2
},
{
"bubbleId": "284c5c3f-51c5-493b-896b-668582b2bdf8",
"type": 2
},
{
"bubbleId": "fc1a7e0b-5688-4d3e-9460-ce66b1b1dcb8",
"type": 2
},
{
"bubbleId": "9280060c-108a-4848-9b63-d3f70bf5767f",
"type": 2
},
{
"bubbleId": "e100b695-1391-42a9-99d4-32d104f566b8",
"type": 2
},
{
"bubbleId": "0ea9ce46-dc6f-459e-be70-95d10ec9d8fc",
"type": 2
},
{
"bubbleId": "8d527e1a-abe9-47a7-809a-f5758880facc",
"type": 1
},
{
"bubbleId": "8e8c4d97-1ce2-4799-8c5d-e7a706e647b2",
"type": 2
},
{
"bubbleId": "52b23bd9-d6d6-4c3d-a548-91c4115f1187",
"type": 2
},
{
"bubbleId": "fbe97373-8028-4c23-8051-aa874bafa726",
"type": 2
},
{
"bubbleId": "e56c87c6-a111-4dfa-988c-508bd8d23025",
"type": 2
},
{
"bubbleId": "19de9ee0-9832-4794-94ad-7fd01e7776c8",
"type": 2
},
{
"bubbleId": "bd40cc5e-d594-492f-9c69-2f10d6e085f0",
"type": 2
},
{
"bubbleId": "34b4c55c-1416-4624-9e90-4e4dbf94ae7e",
"type": 2
},
{
"bubbleId": "77885764-5cc5-49e9-aa29-8f99e1ad91be",
"type": 2
},
{
"bubbleId": "75930adf-1723-4275-9f72-32b5cb770869",
"type": 2
},
{
"bubbleId": "161bc6c0-e489-4209-a507-eb8ab2eab0c7",
"type": 2
},
{
"bubbleId": "e2d87e6f-5ce8-47d9-8fb7-41607132b9c7",
"type": 2
},
{
"bubbleId": "6486a74e-c56f-4616-83f3-82c140ce1505",
"type": 2
},
{
"bubbleId": "0f5cd586-b110-45f0-a08b-1c2980651077",
"type": 2
},
{
"bubbleId": "1a9947b4-e78c-4e0c-b970-78bf2448c539",
"type": 2
},
{
"bubbleId": "e39e4bd6-6a57-49ef-ba9f-ffa88df07b3c",
"type": 2
},
{
"bubbleId": "3d364c16-b345-4455-b5e3-d1bebed5e50e",
"type": 2
},
{
"bubbleId": "cd75e265-c8ca-431d-a44f-e3575ef938ec",
"type": 1
},
{
"bubbleId": "97ea120a-2752-4eff-8800-1107955e1cef",
"type": 2
},
{
"bubbleId": "3b02305c-b40e-4253-8c0f-f09279d9adca",
"type": 2
},
{
"bubbleId": "eca949f4-9095-4a61-b3f7-6a3df9dc65eb",
"type": 1
},
{
"bubbleId": "683d0188-f9a8-42e5-bef1-ca0525d2e1e1",
"type": 2
},
{
"bubbleId": "b46f7ac4-7f08-4125-8c36-969c540cb6ba",
"type": 2
},
{
"bubbleId": "e372205a-4bb1-42ec-8c04-140a6cfe7226",
"type": 2
},
{
"bubbleId": "03a685d5-56c7-4841-a70a-5c4a1cfd1f63",
"type": 2
},
{
"bubbleId": "71a13da4-16a2-4fcb-8927-3f19e4bec1f6",
"type": 2
},
{
"bubbleId": "378bff48-91ef-4ab6-9f84-8f4627e5cdb0",
"type": 2
},
{
"bubbleId": "f1744b48-0fed-43dd-90b1-718b3a04e8e4",
"type": 2
},
{
"bubbleId": "62ccbd6f-911e-4703-bd93-b8a3e226c51e",
"type": 2
},
{
"bubbleId": "a1c0d837-cbd1-4d50-a3e9-b282c6ee182e",
"type": 2
},
{
"bubbleId": "214eb165-8b4a-41d4-8615-3138b4a45a80",
"type": 2
},
{
"bubbleId": "70da7214-a7ca-4441-894f-0d488c38c4cb",
"type": 2
},
{
"bubbleId": "110a76d6-0877-4042-a250-56c116c761eb",
"type": 2
},
{
"bubbleId": "6c9d1371-f13d-4c1d-8e4e-4340f06910e6",
"type": 2
},
{
"bubbleId": "02eb6c0e-46f0-4a50-8e5b-8093c7cd3020",
"type": 2
},
{
"bubbleId": "fe637b17-3216-464f-bf77-48478477d797",
"type": 2
},
{
"bubbleId": "0e5450dd-2bef-4b89-917c-3c36bbd9ec3c",
"type": 1
},
{
"bubbleId": "bb9daf5f-a1f7-4d6a-9eb1-d06a8d0b83ae",
"type": 2
},
{
"bubbleId": "dfc0f138-1ab3-4d9a-b61a-d3f4ac9d573c",
"type": 2
},
{
"bubbleId": "a85650e3-fcce-4955-a93a-cea05e6950d9",
"type": 1
},
{
"bubbleId": "3994efc5-5636-4373-b8a6-497213ab4b25",
"type": 2
},
{
"bubbleId": "fabefd26-2ab8-4238-856a-d71a08c88e13",
"type": 2
},
{
"bubbleId": "2f9f027a-1c9a-4261-bd7e-db0c79a936ae",
"type": 1
},
{
"bubbleId": "62df2253-4853-48ec-ae7b-0f6122a2af83",
"type": 2
},
{
"bubbleId": "67ed4a1d-8990-4e7f-8e60-eabaffb37a2a",
"type": 2
},
{
"bubbleId": "480d8046-8f9e-4d98-9241-2416228d8dcc",
"type": 1
},
{
"bubbleId": "2fb1c9db-852b-47eb-b882-84350f483eef",
"type": 2
},
{
"bubbleId": "e77f3f1e-fe64-45f2-8384-928fc5d51f27",
"type": 2
},
{
"bubbleId": "7c4ee384-daa0-473e-b46a-5d772acc6496",
"type": 2
},
{
"bubbleId": "0a2496fe-b1a8-4ec6-a213-58ef394a5696",
"type": 2
},
{
"bubbleId": "8225bb09-dc6c-405d-b32d-07a74936d279",
"type": 2
},
{
"bubbleId": "3e0c93b6-3958-4f2d-b3b8-d69d5c2eddc1",
"type": 2
},
{
"bubbleId": "32d2dda8-7d76-4375-8d5e-dd76edebe807",
"type": 2
},
{
"bubbleId": "31d03561-91e7-4699-a79b-026d086a9460",
"type": 2
},
{
"bubbleId": "7aa728d5-677b-4e40-a8c6-0973c07e8b73",
"type": 2
},
{
"bubbleId": "260aabde-2bef-438c-9656-dd3b41bc2578",
"type": 2
},
{
"bubbleId": "08cfd30c-f9b4-4c39-b10a-bed5ddb11903",
"type": 2
},
{
"bubbleId": "61011932-0e1b-4455-bc99-0079005e0cd2",
"type": 2
},
{
"bubbleId": "90b43864-7694-41e4-be93-e482058656a1",
"type": 2
},
{
"bubbleId": "352ea863-30cd-4e8f-b7a2-ddbdcfded617",
"type": 2
},
{
"bubbleId": "e998faf9-9108-4886-8b77-931e72c4562a",
"type": 2
},
{
"bubbleId": "5ef06089-fe42-4f12-8319-8052af5eb445",
"type": 2
},
{
"bubbleId": "7a7ba986-3266-4497-8aee-d0cf2432e509",
"type": 2
},
{
"bubbleId": "6448a3c1-9c6d-48d4-abe1-72a197c85fc0",
"type": 2
},
{
"bubbleId": "ca7d7730-edef-4be6-8412-1ae67c4b8d64",
"type": 2
},
{
"bubbleId": "bd95edb2-ccaa-4daf-bf40-f37f6c5c10cd",
"type": 2
},
{
"bubbleId": "37da15b0-16a9-4221-9924-2f8a30abbfa5",
"type": 2
},
{
"bubbleId": "58b466ec-397d-43aa-88e2-e3929656fd83",
"type": 2
},
{
"bubbleId": "0d55d26a-2b11-4f05-b212-9eae268954ae",
"type": 2
},
{
"bubbleId": "94a4aea3-c369-4713-b2bd-50e80dc629e5",
"type": 2
},
{
"bubbleId": "33f4c8f0-9d45-4651-bd03-31e7154a2dfb",
"type": 2
},
{
"bubbleId": "100771a1-7a35-4169-b9c0-53e69046d754",
"type": 2
},
{
"bubbleId": "0149bf71-7223-4d37-98d8-63069678e7c6",
"type": 2
},
{
"bubbleId": "72ea8411-4513-41d5-a820-06e3468e0b85",
"type": 2
},
{
"bubbleId": "ca49ddc7-3d50-4594-af55-de3cbf37b284",
"type": 2
},
{
"bubbleId": "d13572e7-c513-4bcd-a6fa-a60aeeeed649",
"type": 2
},
{
"bubbleId": "f525a110-8fc2-4bbc-9068-7a676a7afef3",
"type": 2
},
{
"bubbleId": "eb593ccb-d934-4172-b77a-18275f5bf053",
"type": 2
},
{
"bubbleId": "104fcb2b-613a-43c1-9e29-6af05678159d",
"type": 2
},
{
"bubbleId": "79e4ac41-3448-4090-a59d-08c3ec06eb70",
"type": 2
},
{
"bubbleId": "94fc91db-f01d-4312-bc3b-4d24d88784f4",
"type": 2
},
{
"bubbleId": "970009a4-dddb-4dfa-9122-26bb40404e1c",
"type": 2
},
{
"bubbleId": "ed181675-035d-4e0d-a768-63883960b0d4",
"type": 2
},
{
"bubbleId": "c9722bde-550e-400c-bf1d-f4b8a127df84",
"type": 2
},
{
"bubbleId": "1ebf8507-ef43-4054-9a45-8d40bc90f680",
"type": 2
},
{
"bubbleId": "ba3d5a12-102f-4a92-94c9-247bef616690",
"type": 2
},
{
"bubbleId": "f8792266-8ca4-4ea6-aebf-8e6366cfc5f7",
"type": 2
},
{
"bubbleId": "14b8c56c-592a-4139-980f-47a397bb58d6",
"type": 2
},
{
"bubbleId": "1c543f8b-16fc-4d60-9fa9-3244d7468d7f",
"type": 2
},
{
"bubbleId": "46ef4e4d-41f5-4748-bcb6-225be305eb83",
"type": 2
},
{
"bubbleId": "aadcafd9-26f0-49cb-973c-58044f355b35",
"type": 2
},
{
"bubbleId": "4f0844ce-4fcb-4e9f-8aee-5a9df27c8099",
"type": 2
},
{
"bubbleId": "1d84a503-3ac8-4a01-8769-1e15b31dbaa5",
"type": 2
},
{
"bubbleId": "bbb21013-4a6f-4e3a-b9fc-88fe3d83d120",
"type": 2
},
{
"bubbleId": "c710b03e-519d-4784-bb95-3d24144f22a3",
"type": 1
},
{
"bubbleId": "0840707e-43b4-4962-ae5f-87369d07ad6e",
"type": 2
},
{
"bubbleId": "c4147f56-8e29-489d-a714-cbe720437b9b",
"type": 2
}
],
"conversationMap": {},
"status": "completed",
"context": {
"composers": [],
"selectedCommits": [],
"selectedPullRequests": [],
"selectedImages": [],
"folderSelections": [],
"fileSelections": [],
"selections": [],
"terminalSelections": [],
"selectedDocs": [],
"externalLinks": [],
"cursorRules": [],
"cursorCommands": [],
"gitPRDiffSelections": [],
"subagentSelections": [],
"browserSelections": [],
"mentions": {
"composers": {},
"selectedCommits": {},
"selectedPullRequests": {},
"gitDiff": [],
"gitDiffFromBranchToMain": [],
"selectedImages": {},
"folderSelections": {
"{\"relativePath\":\"common/trivy-operator\",\"addedWithoutMention\":false}": []
},
"fileSelections": {},
"terminalFiles": {},
"selections": {},
"terminalSelections": {
"{\"uri\":\"vscode-terminal:/home-ruslanpi-Documents-repos-lmru-devops-argocd-apps/1\",\"range\":{\"startLineNumber\":7,\"startColumn\":1,\"endLineNumber\":13,\"endColumn\":74,\"selectionStartLineNumber\":7,\"selectionStartColumn\":1,\"positionLineNumber\":13,\"positionColumn\":74},\"text\":\"```bash\\n' | sort -V\\n4.2.8 FAIL=6 HIGH Ensure that the --hostname-override argument is not set\\n5.2.2 FAIL=10 HIGH Minimize the admission of privileged containers\\n5.2.3 FAIL=2 HIGH Minimize the admission of containers wishing to share the host process ID namespace\\n5.2.5 FAIL=38 HIGH Minimize the admission of containers wishing to share the host network namespace\\n5.2.13 FAIL=2 MEDIUM Minimize the admission of containers which use HostPorts\\n5.7.3 FAIL=4 HIGH Apply Security Context to Your Pods and Containers\\n```\"}": [
{
"uuid": "dc9d7f22-8577-463e-be36-d58d1f41c6b0"
}
]
},
"selectedDocs": {},
"externalLinks": {
"https://github.com/giantswarm/starboard-exporter": [
{
"uuid": "1077"
}
],
"https://aquasecurity.github.io/trivy-operator/v0.25.0/getting-started/installation/configuration/": [
{
"uuid": "1085"
}
]
},
"diffHistory": [],
"cursorRules": {},
"cursorCommands": {},
"uiElementSelections": [],
"consoleLogs": [],
"ideEditorsState": [],
"gitPRDiffSelections": {},
"subagentSelections": {},
"browserSelections": {}
}
},
"generatingBubbleIds": [],
"isReadingLongFile": false,
"codeBlockData": {},
"originalFileStates": {
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/values/values-global.yaml": {
"content": "# Default values for the trivy-operator Helm chart, these are used to render\n# the templates into valid k8s Resources.\n\n# -- global values provide a centralized configuration for 'image.registry', reducing the potential for errors.\n# If left blank, the chart will default to the individually set 'image.registry' values\nglobal:\n image:\n registry: \"docker-security.art.lmru.tech\"\n\n# -- managedBy is similar to .Release.Service but allows to overwrite the value\nmanagedBy: Helm\n\n# -- targetNamespace defines where you want trivy-operator to operate. By\n# default, it's a blank string to select all namespaces, but you can specify\n# another namespace, or a comma separated list of namespaces.\ntargetNamespaces: \"\"\n\n# -- excludeNamespaces is a comma separated list of namespaces (or glob patterns)\n# to be excluded from scanning. Only applicable in the all namespaces install\n# mode, i.e. when the targetNamespaces values is a blank string.\nexcludeNamespaces:\n#- kube-system\n- kube-public\n- kube-node-lease\n- ingress-nginx\n\n# -- extraEnv is a list of extra environment variables for the trivy-operator.\nextraEnv: []\n\n# -- hostAliases for `deployment` (TrivyOperator) and `statefulset` (TrivyServer)\n\nhostAliases: []\n# - ip: \"127.0.0.1\"\n# hostnames:\n# - \"foo.local\"\n# - \"bar.local\"\n# - ip: \"10.1.2.3\"\n# hostnames:\n# - \"foo.remote\"\n# - \"bar.remote\"\n\n# -- targetWorkloads is a comma seperated list of Kubernetes workload resources\n# to be included in the vulnerability and config-audit scans\n# if left blank, all workload resources will be scanned\ntargetWorkloads: \"pod,replicaset,replicationcontroller,statefulset,daemonset,cronjob,job\"\n\n# -- nameOverride override operator name\nnameOverride: \"\"\n\n# -- fullnameOverride override operator full name\nfullnameOverride: \"trivy-operator\"\n\noperator:\n # -- namespace to install the operator, defaults to the .Release.Namespace\n namespace: \"\"\n # -- replicas the number of replicas of the operator's pod\n replicas: 1\n\n # -- number of old history to retain to allow rollback (if not set, default Kubernetes value is set to 10)\n revisionHistoryLimit: 5\n\n # -- additional annotations for the operator deployment\n annotations: {}\n\n # -- additional labels for the operator deployment\n labels: {}\n\n # -- additional labels for the operator pod\n podLabels:\n prometheus.deckhouse.io/custom-target: trivy-operator\n\n # -- leaderElectionId determines the name of the resource that leader election\n # will use for holding the leader lock.\n leaderElectionId: \"trivyoperator-lock\"\n\n # -- logDevMode the flag to enable development mode (more human-readable output, extra stack traces and logging information, etc)\n logDevMode: false\n\n # -- scanJobTTL the set automatic cleanup time after the job is completed\n scanJobTTL: \"\"\n\n # -- scanSecretTTL set an automatic cleanup for scan job secrets\n scanSecretTTL: \"\"\n\n # -- scanJobTimeout the length of time to wait before giving up on a scan job\n scanJobTimeout: 5m\n\n # -- scanJobsConcurrentLimit the maximum number of scan jobs create by the operator\n scanJobsConcurrentLimit: 5\n\n # -- scanNodeCollectorLimit the maximum number of node collector jobs create by the operator\n scanNodeCollectorLimit: 1\n\n # -- scanJobsRetryDelay the duration to wait before retrying a failed scan job\n scanJobsRetryDelay: 30s\n\n # -- the flag to enable vulnerability scanner\n vulnerabilityScannerEnabled: false\n # -- the flag to enable sbom generation, required for enabling ClusterVulnerabilityReports\n sbomGenerationEnabled: false\n # -- the flag to enable cluster sbom cache generation\n clusterSbomCacheEnabled: false\n # -- scannerReportTTL the flag to set how long a report should exist. \"\" means that the ScannerReportTTL feature is disabled\n scannerReportTTL: \"20h\"\n # -- cacheReportTTL the flag to set how long a cluster sbom report should exist. \"\" means that the cacheReportTTL feature is disabled\n cacheReportTTL: \"48h\"\n # -- configAuditScannerEnabled the flag to enable configuration audit scanner\n configAuditScannerEnabled: true\n # -- rbacAssessmentScannerEnabled the flag to enable rbac assessment scanner\n rbacAssessmentScannerEnabled: false\n # -- infraAssessmentScannerEnabled the flag to enable infra assessment scanner\n infraAssessmentScannerEnabled: true\n # -- clusterComplianceEnabled the flag to enable cluster compliance scanner\n clusterComplianceEnabled: true\n # -- batchDeleteLimit the maximum number of config audit reports deleted by the operator when the plugin's config has changed.\n batchDeleteLimit: 10\n # -- vulnerabilityScannerScanOnlyCurrentRevisions the flag to only create vulnerability scans on the current revision of a deployment.\n vulnerabilityScannerScanOnlyCurrentRevisions: false\n # -- configAuditScannerScanOnlyCurrentRevisions the flag to only create config audit scans on the current revision of a deployment.\n configAuditScannerScanOnlyCurrentRevisions: true\n # -- batchDeleteDelay the duration to wait before deleting another batch of config audit reports.\n batchDeleteDelay: 10s\n # -- accessGlobalSecretsAndServiceAccount The flag to enable access to global secrets/service accounts to allow `vulnerability scan job` to pull images from private registries\n accessGlobalSecretsAndServiceAccount: false\n # -- builtInTrivyServer The flag enables the usage of built-in trivy server in cluster. It also overrides the following trivy params with built-in values\n # trivy.mode = ClientServer and serverURL = http://<serverServiceName>.<trivy operator namespace>:4975\n builtInTrivyServer: false\n # -- builtInServerRegistryInsecure is the flag to enable insecure connection from the built-in Trivy server to the registry.\n builtInServerRegistryInsecure: false\n # -- controllerCacheSyncTimeout the duration to wait for controller resources cache sync (default: 5m).\n controllerCacheSyncTimeout: \"5m\"\n\n # -- trivyServerHealthCheckCacheExpiration The flag to set the interval for trivy server health cache before it invalidate\n trivyServerHealthCheckCacheExpiration: 10h\n\n # -- metricsFindingsEnabled the flag to enable metrics for findings\n metricsFindingsEnabled: true\n\n # -- metricsVulnIdEnabled the flag to enable metrics about cve vulns id\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsVulnIdEnabled: false\n\n # -- exposedSecretScannerEnabled the flag to enable exposed secret scanner\n exposedSecretScannerEnabled: false\n\n # -- MetricsExposedSecretInfo the flag to enable metrics about exposed secrets\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsExposedSecretInfo: false\n\n # -- MetricsConfigAuditInfo the flag to enable metrics about configuration audits\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsConfigAuditInfo: false\n\n # -- MetricsRbacAssessmentInfo the flag to enable metrics about Rbac Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsRbacAssessmentInfo: false\n\n # -- MetricsInfraAssessmentInfo the flag to enable metrics about Infra Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsInfraAssessmentInfo: false\n\n # -- MetricsImageInfo the flag to enable metrics about Image Information of scanned images\n # This information has image os information including os family, name/version, and if end of service life has been reached\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsImageInfo: false\n\n # -- MetricsClusterComplianceInfo the flag to enable metrics about Cluster Compliance\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsClusterComplianceInfo: true\n\n # -- serverAdditionalAnnotations the flag to set additional annotations for the trivy server pod\n serverAdditionalAnnotations: {}\n\n # -- webhookBroadcastURL the flag to set reports should be sent to a webhook endpoint. \"\" means that the webhookBroadcastURL feature is disabled\n webhookBroadcastURL: \"\"\n\n # -- webhookBroadcastTimeout the flag to set timeout for webhook requests if webhookBroadcastURL is enabled\n webhookBroadcastTimeout: 30s\n\n # -- webhookBroadcastCustomHeaders the flag to set webhook endpoint sent with custom defined headers if webhookBroadcastURL is enabled\n webhookBroadcastCustomHeaders: \"\"\n\n # -- webhookSendDeletedReports the flag to enable sending deleted reports if webhookBroadcastURL is enabled\n webhookSendDeletedReports: false\n\n # -- privateRegistryScanSecretsNames is map of namespace:secrets, secrets are comma seperated which can be used to authenticate in private registries in case if there no imagePullSecrets provided example : {\"mynamespace\":\"mySecrets,anotherSecret\"}\n privateRegistryScanSecretsNames: {}\n\n # -- mergeRbacFindingWithConfigAudit the flag to enable merging rbac finding with config-audit report\n mergeRbacFindingWithConfigAudit: false\n\n # -- httpProxy is the HTTP proxy used by Trivy operator to download the default policies from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy operator to download the default policies from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply OPERATOR_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply OPERATOR_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\nimage:\n registry: \"mirror.gcr.io\"\n repository: \"aquasec/trivy-operator\"\n # -- tag is an override of the image tag, which is by default set by the\n # appVersion field in Chart.yaml.\n tag: \"\"\n # -- pullPolicy set the operator pullPolicy\n pullPolicy: IfNotPresent\n # -- pullSecrets set the operator pullSecrets\n pullSecrets: []\n\n# -- service only expose a metrics endpoint for prometheus to scrape,\n# trivy-operator does not have a user interface.\nservice:\n # -- if true, the Service doesn't allocate any IP\n headless: false\n # -- port exposed by the Service\n metricsPort: 80\n # -- annotations added to the operator's service\n annotations: {}\n # -- appProtocol of the monitoring service\n metricsAppProtocol: TCP\n # -- the Service type\n type: ClusterIP\n # -- the nodeport to use when service type is LoadBalancer or NodePort. If not set, Kubernetes automatically select one.\n nodePort:\n\n # -- Prometheus ServiceMonitor configuration -- to install the trivy operator with the ServiceMonitor\n # you must have Prometheus already installed and running. If you do not have Prometheus installed, enabling this will\n # have no effect.\nserviceMonitor:\n # -- enabled determines whether a serviceMonitor should be deployed\n enabled: false\n # -- The namespace where Prometheus expects to find service monitors\n namespace: ~\n # -- Interval at which metrics should be scraped. If not specified Prometheus global scrape interval is used.\n interval: ~\n # -- Additional annotations for the serviceMonitor\n annotations: {}\n # -- Additional labels for the serviceMonitor\n labels: {}\n # -- HonorLabels chooses the metrics labels on collisions with target labels\n honorLabels: true\n # -- EndpointAdditionalProperties allows setting additional properties on the endpoint such as relabelings, metricRelabelings etc.\n endpointAdditionalProperties: {}\n\nreportMetrics:\n enabled: true\n image:\n registry: registry.k8s.io\n repository: kube-state-metrics\n tag: 2.18.0\n pullPolicy: IfNotPresent\n serviceAccount:\n create: true\n name: \"\"\n podAnnotations: {}\n podLabels: {}\n service:\n customTarget: custom-trivy-kube-state-metrics\n port: 8080\n path: /metrics\n sampleLimit: 15000\n resources:\n requests:\n cpu: 50m\n memory: 128Mi\n limits:\n cpu: 200m\n memory: 256Mi\n\ntrivyOperator:\n # -- vulnerabilityReportsPlugin the name of the plugin that generates vulnerability reports `Trivy`\n vulnerabilityReportsPlugin: \"Trivy\"\n # -- configAuditReportsPlugin the name of the plugin that generates config audit reports.\n configAuditReportsPlugin: \"Trivy\"\n # -- scanJobCompressLogs control whether scanjob output should be compressed or plain\n scanJobCompressLogs: false\n # -- scanJobAffinity affinity to be applied to the scanner pods and node-collector\n scanJobAffinity: {}\n # -- scanJobTolerations tolerations to be applied to the scanner pods so that they can run on nodes with matching taints\n scanJobTolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- scanJobNodeSelector nodeSelector to be applied to the scanner pods so that they can run on nodes with matching labels\n scanJobNodeSelector: {}\n # -- If you do want to specify nodeSelector, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobNodeSelector:'.\n # nodeType: worker\n # cpu: sandylake\n # teamOwner: operators\n\n # -- scanJobCustomVolumesMount add custom volumes mount to the scan job\n scanJobCustomVolumesMount: []\n # - name: var-lib-etcd\n # mountPath: /var/lib/etcd\n # readOnly: true\n\n # -- scanJobCustomVolumes add custom volumes to the scan job\n scanJobCustomVolumes: []\n # - name: var-lib-etcd\n # hostPath:\n # path: /var/lib/etcd\n\n # -- useGCRServiceAccount the flag to enable the usage of GCR service account for scanning images in GCR\n useGCRServiceAccount: true\n # -- scanJobAutomountServiceAccountToken the flag to enable automount for service account token on scan job\n scanJobAutomountServiceAccountToken: false\n\n # -- scanJobAnnotations comma-separated representation of the annotations which the user wants the scanner jobs and pods to be\n # annotated with. Example: `foo=bar,env=stage` will annotate the scanner jobs and pods with the annotations `foo: bar` and `env: stage`\n scanJobAnnotations: \"\"\n\n # -- scanJobPodTemplateLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the scanner pods with the labels `foo: bar` and `env: stage`\n scanJobPodTemplateLabels: \"\"\n\n # -- skipInitContainers when this flag is set to true, the initContainers will be skipped for the scanner and node collector pods\n skipInitContainers: false\n\n # -- scanJobPodTemplatePodSecurityContext podSecurityContext the user wants the scanner and node collector pods to be amended with.\n # Example:\n # RunAsUser: 10000\n # RunAsGroup: 10000\n # RunAsNonRoot: true\n scanJobPodTemplatePodSecurityContext: {}\n\n # -- scanJobPodTemplateContainerSecurityContext SecurityContext the user wants the scanner and node collector containers (and their\n # initContainers) to be amended with.\n scanJobPodTemplateContainerSecurityContext:\n allowPrivilegeEscalation: false\n capabilities:\n drop:\n - ALL\n privileged: false\n readOnlyRootFilesystem: true\n # -- For filesystem scanning, Trivy needs to run as the root user\n # runAsUser: 0\n\n # -- scanJobPodPriorityClassName Priority class name to be set on the pods created by trivy operator jobs. This accepts a string value\n scanJobPodPriorityClassName: \"\"\n\n # -- reportResourceLabels comma-separated scanned resource labels which the user wants to include in the Prometheus\n # metrics report. Example: `owner,app`\n reportResourceLabels: \"\"\n\n # -- reportRecordFailedChecksOnly flag is to record only failed checks on misconfiguration reports (config-audit and rbac assessment)\n reportRecordFailedChecksOnly: true\n\n # -- skipResourceByLabels comma-separated labels keys which trivy-operator will skip scanning on resources with matching labels\n skipResourceByLabels: \"\"\n\n # -- metricsResourceLabelsPrefix Prefix that will be prepended to the labels names indicated in `reportResourceLabels`\n # when including them in the Prometheus metrics\n metricsResourceLabelsPrefix: \"k8s_label_\"\n\n # -- additionalReportLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the reports with the labels `foo: bar` and `env: stage`\n additionalReportLabels: \"\"\n\n # -- policiesConfig Custom Rego Policies to be used by the config audit scanner\n # See https://github.com/aquasecurity/trivy-operator/blob/main/docs/tutorials/writing-custom-configuration-audit-policies.md for more details.\n policiesConfig: \"\"\n\n # -- excludeImages is comma separated glob patterns for excluding images from scanning.\n # Example: pattern: `k8s.gcr.io/*/*` will exclude image: `k8s.gcr.io/coredns/coredns:v1.8.0`.\n excludeImages: \"\"\n\ntrivy:\n # -- createConfig indicates whether to create config objects\n createConfig: true\n image:\n # -- registry of the Trivy image\n registry: mirror.gcr.io\n # -- repository of the Trivy image\n repository: aquasec/trivy\n # -- tag version of the Trivy image\n tag: 0.60.0\n # -- imagePullSecret is the secret name to be used when pulling trivy image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n\n # -- pullPolicy is the imge pull policy used for trivy image , valid values are (Always, Never, IfNotPresent)\n pullPolicy: IfNotPresent\n\n # -- mode is the Trivy client mode. Either Standalone or ClientServer. Depending\n # on the active mode other settings might be applicable or required.\n mode: Standalone\n\n # -- sbomSources trivy will try to retrieve SBOM from the specified sources (oci,rekor)\n sbomSources: \"\"\n\n # -- includeDevDeps include development dependencies in the report (supported: npm, yarn) (default: false)\n # note: this flag is only applicable when trivy.command is set to filesystem\n includeDevDeps: false\n\n # -- whether to use a storage class for trivy server or emptydir (one mey want to use ephemeral storage)\n storageClassEnabled: true\n\n # -- storageClassName is the name of the storage class to be used for trivy server PVC. If empty, tries to find default storage class\n storageClassName: \"\"\n\n # -- storageSize is the size of the trivy server PVC\n storageSize: \"5Gi\"\n\n # -- labels is the extra labels to be used for trivy server statefulset\n labels: {}\n\n # -- podLabels is the extra pod labels to be used for trivy server\n podLabels: {}\n\n # -- priorityClassName is the name of the priority class used for trivy server\n priorityClassName: \"\"\n\n # -- additionalVulnerabilityReportFields is a comma separated list of additional fields which\n # can be added to the VulnerabilityReport. Supported parameters: Description, Links, CVSS, Target, Class, PackagePath and PackageType\n additionalVulnerabilityReportFields: \"\"\n\n # -- httpProxy is the HTTP proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- Registries without SSL. There can be multiple registries with different keys.\n nonSslRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- sslCertDir can be used to override the system default locations for SSL certificate files directory, example: /ssl/certs\n sslCertDir: ~\n\n # -- The registry to which insecure connections are allowed. There can be multiple registries with different keys.\n insecureRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- Mirrored registries. There can be multiple registries with different keys.\n # Make sure to quote registries containing dots\n registry:\n mirror: {}\n # \"docker.io\": docker-mirror.example.com\n\n # -- severity is a comma separated list of severity levels reported by Trivy.\n severity: UNKNOWN,HIGH,CRITICAL\n\n # -- slow this flag is to use less CPU/memory for scanning though it takes more time than normal scanning. It fits small-footprint\n slow: true\n # -- ignoreUnfixed is the flag to show only fixed vulnerabilities in\n # vulnerabilities reported by Trivy. Set to true to enable it.\n #\n ignoreUnfixed: true\n # -- a comma separated list of file paths for Trivy to skip\n skipFiles: # -- a comma separated list of directories for Trivy to skip\n\n skipDirs:\n\n # -- offlineScan is the flag to enable the offline scan functionality in Trivy\n # This will prevent outgoing HTTP requests, e.g. to search.maven.org\n offlineScan: false\n\n # -- timeout is the duration to wait for scan completion.\n timeout: \"5m0s\"\n\n # -- ignoreFile can be used to tell Trivy to ignore vulnerabilities by ID (one per line)\n ignoreFile: ~\n # ignoreFile:\n # - CVE-1970-0001\n # - CVE-1970-0002\n\n # -- ignorePolicy can be used to tell Trivy to ignore vulnerabilities by a policy\n # If multiple policies would match, then the most specific one has precedence over the others.\n # See https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#by-open-policy-agent for more details.\n # See https://github.com/aquasecurity/trivy/blob/v0.19.2/contrib/example_policy/basic.rego for more details on ignorePolicy filtering.\n #\n # ignorePolicy.application.my-app-.: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"application\" with the name pattern \"my-app-*\"\n # ignorePolicy.kube-system: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"kube-system\"\n # ignorePolicy: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all other workloads\n\n # -- vulnType can be used to tell Trivy to filter vulnerabilities by a pkg-type (library, os)\n vulnType: ~\n\n # -- resources resource requests and limits for scan job containers\n resources:\n requests:\n cpu: 100m\n memory: 100M\n # ephemeralStorage: \"2Gi\"\n limits:\n cpu: 500m\n memory: 1Gi\n # ephemeralStorage: \"2Gi\"\n\n # -- githubToken is the GitHub access token used by Trivy to download the vulnerabilities\n # database from GitHub. Only applicable in Standalone mode.\n githubToken: ~\n\n # -- serverURL is the endpoint URL of the Trivy server. Required in ClientServer mode.\n #\n # serverURL: \"https://trivy.trivy:4975\"\n\n # -- clientServerSkipUpdate is the flag to enable skip databases update for Trivy client.\n # Only applicable in ClientServer mode.\n clientServerSkipUpdate: false\n\n # -- skipJavaDBUpdate is the flag to enable skip Java index databases update for Trivy client.\n skipJavaDBUpdate: false\n\n # -- serverInsecure is the flag to enable insecure connection to the Trivy server.\n serverInsecure: false\n\n # -- serverToken is the token to authenticate Trivy client with Trivy server. Only\n # applicable in ClientServer mode.\n serverToken: ~\n\n # -- existingSecret if a secret containing gitHubToken, serverToken or serverCustomHeaders has been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: trivy.githubToken, trivy.serverToken, trivy.serverCustomHeaders\n # Overrides trivy.gitHubToken, trivy.serverToken, trivy.serverCustomHeaders values.\n # Note: The secret has to be named \"trivy-operator-trivy-config\".\n # existingSecret: true\n\n # -- serverTokenHeader is the name of the HTTP header used to send the authentication\n # token to Trivy server. Only application in ClientServer mode when\n # trivy.serverToken is specified.\n serverTokenHeader: \"Trivy-Token\"\n\n # -- serverCustomHeaders is a comma separated list of custom HTTP headers sent by\n # Trivy client to Trivy server. Only applicable in ClientServer mode.\n serverCustomHeaders: ~\n # serverCustomHeaders: \"foo=bar\"\n\n dbRegistry: \"mirror.gcr.io\"\n dbRepository: \"aquasec/trivy-db\"\n\n # -- The username for dbRepository authentication\n #\n dbRepositoryUsername: ~\n\n # -- The password for dbRepository authentication\n #\n dbRepositoryPassword: ~\n\n # -- javaDbRegistry is the registry for the Java vulnerability database.\n javaDbRegistry: \"mirror.gcr.io\"\n javaDbRepository: \"aquasec/trivy-java-db\"\n\n # -- The Flag to enable insecure connection for downloading trivy-db via proxy (air-gaped env)\n #\n dbRepositoryInsecure: \"false\"\n\n # -- The Flag to enable the usage of builtin rego policies by default, these policies are downloaded by default from mirror.gcr.io/aquasec/trivy-checks\n #\n useBuiltinRegoPolicies: \"false\"\n # -- The Flag to enable the usage of external rego policies config-map, this should be used when the user wants to use their own rego policies\n #\n externalRegoPoliciesEnabled: false\n # -- To enable the usage of embedded rego policies, set the flag useEmbeddedRegoPolicies. This should serve as a fallback for air-gapped environments.\n # When useEmbeddedRegoPolicies is set to true, useBuiltinRegoPolicies should be set to false.\n useEmbeddedRegoPolicies: \"true\"\n\n # -- The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner\n #\n supportedConfigAuditKinds: \"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota\"\n\n # -- command. One of `image`, `filesystem` or `rootfs` scanning, depending on the target type required for the scan.\n # For 'filesystem' and `rootfs` scanning, ensure that the `trivyOperator.scanJobPodTemplateContainerSecurityContext` is configured\n # to run as the root user (runAsUser = 0).\n command: image\n # -- imageScanCacheDir the flag to set custom path for trivy image scan `cache-dir` parameter.\n # Only applicable in image scan mode.\n imageScanCacheDir: \"/tmp/trivy/.cache\"\n # -- filesystemScanCacheDir the flag to set custom path for trivy filesystem scan `cache-dir` parameter.\n # Only applicable in filesystem scan mode.\n filesystemScanCacheDir: \"/var/trivyoperator/trivy-db\"\n # -- serverUser this param is the server user to be used to download db from private registry\n serverUser: \"\"\n # -- serverPassword this param is the server user to be used to download db from private registry\n serverPassword: \"\"\n # -- serverServiceName this param is the server service name to be used in cluster\n serverServiceName: \"trivy-service\"\n # -- debug One of `true` or `false`. Enables debug mode.\n debug: false\n\n server:\n # -- resources set trivy-server resource\n resources:\n requests:\n cpu: 200m\n memory: 512Mi\n # ephemeral-storage: \"2Gi\"\n limits:\n cpu: 1\n memory: 1Gi\n # ephemeral-storage: \"2Gi\"\n\n # -- podSecurityContext set trivy-server podSecurityContext\n podSecurityContext:\n runAsUser: 65534\n runAsNonRoot: true\n fsGroup: 65534\n\n # -- securityContext set trivy-server securityContext\n securityContext:\n privileged: false\n readOnlyRootFilesystem: true\n\n # -- the number of replicas of the trivy-server\n replicas: 1\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply TRIVY_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply TRIVY_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\ncompliance:\n # -- failEntriesLimit the flag to limit the number of fail entries per control check in the cluster compliance detail report\n # this limit is for preventing the report from being too large per control checks\n failEntriesLimit: 10\n # -- reportType this flag control the type of report generated (summary or all)\n reportType: all\n # -- cron this flag control the cron interval for compliance report generation\n cron: 0 */6 * * *\n # -- specs is a list of compliance specs to be used by the cluster compliance scanner\n # - k8s-cis-1.23\n # - k8s-nsa-1.0\n # - k8s-pss-baseline-0.1\n # - k8s-pss-restricted-0.1\n # - eks-cis-1.4\n # - rke2-cis-1.24\n specs:\n - k8s-cis-1.23\n - k8s-nsa-1.0\n - k8s-pss-baseline-0.1\n - k8s-pss-restricted-0.1\n\nrbac:\n create: true\nserviceAccount:\n # -- Specifies whether a service account should be created.\n create: true\n annotations: {}\n # -- name specifies the name of the k8s Service Account. If not set and create is\n # true, a name is generated using the fullname template.\n name: \"\"\n\n# -- podAnnotations annotations added to the operator's pod\npodAnnotations:\n prometheus.deckhouse.io/port: \"8080\"\n\npodSecurityContext: {}\n# fsGroup: 2000\n\n# -- securityContext security context\nsecurityContext:\n privileged: false\n allowPrivilegeEscalation: false\n readOnlyRootFilesystem: true\n capabilities:\n drop:\n - ALL\n\nvolumeMounts:\n# do not remove , required for policies bundle\n- mountPath: /tmp\n name: cache-policies\n readOnly: false\n\nvolumes:\n# do not remove , required for policies bundle\n- name: cache-policies\n emptyDir: {}\n\nresources: {}\n# -- We usually recommend not to specify default resources and to leave this as a conscious\n# choice for the user. This also increases chances charts run on environments with little\n# resources, such as Minikube. If you do want to specify resources, uncomment the following\n# lines, adjust them as necessary, and remove the curly braces after 'resources:'.\n# limits:\n# cpu: 100m\n# memory: 128Mi\n# requests:\n# cpu: 100m\n# memory: 128Mi\n\n# -- nodeSelector set the operator nodeSelector\n#nodeSelector: {}\n\nnodeSelector:\n node-role.k8s.lmru.tech/application: ''\n\n# -- tolerations set the operator tolerations\ntolerations: []\n\n# -- affinity set the operator affinity\naffinity: {}\n\n# -- priorityClassName set the operator priorityClassName\npriorityClassName: \"\"\n\n# -- automountServiceAccountToken the flag to enable automount for service account token\nautomountServiceAccountToken: true\n\npoliciesBundle:\n # -- registry of the policies bundle\n registry: mirror.gcr.io\n # -- repository of the policies bundle\n repository: aquasec/trivy-checks\n # -- tag version of the policies bundle\n tag: 1\n # -- registryUser is the user for the registry\n registryUser: ~\n # -- registryPassword is the password for the registry\n registryPassword: ~\n # -- existingSecret if a secret containing registry credentials that have been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: policies.bundle.oci.user, policies.bundle.oci.password\n # Overrides policiesBundle.registryUser, policiesBundle.registryPassword values.\n # Note: The secret has to be named \"trivy-operator\".\n existingSecret: false\n # -- insecure is the flag to enable insecure connection to the policy bundle registry\n insecure: false\n\nnodeCollector:\n # -- useNodeSelector determine if to use nodeSelector (by auto detecting node name) with node-collector scan job\n useNodeSelector: false\n # -- registry of the node-collector image\n registry: docker-security.art.lmru.tech\n # -- repository of the node-collector image\n repository: aquasec/node-collector\n # -- tag version of the node-collector image\n tag: 0.3.1\n # -- imagePullSecret is the secret name to be used when pulling node-collector image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n # -- excludeNodes comma-separated node labels that the node-collector job should exclude from scanning (example kubernetes.io/arch=arm64,team=dev)\n excludeNodes: # -- tolerations to be applied to the node-collector so that they can run on nodes with matching taints\n\n tolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- node-collector pod volume mounts definition for collecting config files information\n volumeMounts:\n - name: var-lib-etcd\n mountPath: /var/lib/etcd\n readOnly: true\n - name: var-lib-kubelet\n mountPath: /var/lib/kubelet\n readOnly: true\n - name: var-lib-kube-scheduler\n mountPath: /var/lib/kube-scheduler\n readOnly: true\n - name: var-lib-kube-controller-manager\n mountPath: /var/lib/kube-controller-manager\n readOnly: true\n - name: etc-systemd\n mountPath: /etc/systemd\n readOnly: true\n - name: lib-systemd\n mountPath: /lib/systemd/\n readOnly: true\n - name: etc-kubernetes\n mountPath: /etc/kubernetes\n readOnly: true\n - name: etc-cni-netd\n mountPath: /etc/cni/net.d/\n readOnly: true\n # -- node-collector pod volumes definition for collecting config files information\n volumes:\n - name: var-lib-etcd\n hostPath:\n path: /var/lib/etcd\n - name: var-lib-kubelet\n hostPath:\n path: /var/lib/kubelet\n - name: var-lib-kube-scheduler\n hostPath:\n path: /var/lib/kube-scheduler\n - name: var-lib-kube-controller-manager\n hostPath:\n path: /var/lib/kube-controller-manager\n - name: etc-systemd\n hostPath:\n path: /etc/systemd\n - name: lib-systemd\n hostPath:\n path: /lib/systemd\n - name: etc-kubernetes\n hostPath:\n path: /etc/kubernetes\n - name: etc-cni-netd\n hostPath:\n path: /etc/cni/net.d/\n",
"firstEditBubbleId": "f5822428-f73d-44dc-82fd-d549351d874d",
"isNewlyCreated": false,
"newlyCreatedFolders": []
},
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/values/values-global.yaml": {
"content": "# Default values for the trivy-operator Helm chart, these are used to render\n# the templates into valid k8s Resources.\n\n# -- global values provide a centralized configuration for 'image.registry', reducing the potential for errors.\n# If left blank, the chart will default to the individually set 'image.registry' values\nglobal:\n image:\n registry: \"docker-security.art.lmru.tech\"\n\n# -- managedBy is similar to .Release.Service but allows to overwrite the value\nmanagedBy: Helm\n\n# -- targetNamespace defines where you want trivy-operator to operate. By\n# default, it's a blank string to select all namespaces, but you can specify\n# another namespace, or a comma separated list of namespaces.\ntargetNamespaces: \"\"\n\n# -- excludeNamespaces is a comma separated list of namespaces (or glob patterns)\n# to be excluded from scanning. Only applicable in the all namespaces install\n# mode, i.e. when the targetNamespaces values is a blank string.\nexcludeNamespaces:\n#- kube-system\n- kube-public\n- kube-node-lease\n- ingress-nginx\n\n# -- extraEnv is a list of extra environment variables for the trivy-operator.\nextraEnv: []\n\n# -- hostAliases for `deployment` (TrivyOperator) and `statefulset` (TrivyServer)\n\nhostAliases: []\n# - ip: \"127.0.0.1\"\n# hostnames:\n# - \"foo.local\"\n# - \"bar.local\"\n# - ip: \"10.1.2.3\"\n# hostnames:\n# - \"foo.remote\"\n# - \"bar.remote\"\n\n# -- targetWorkloads is a comma seperated list of Kubernetes workload resources\n# to be included in the vulnerability and config-audit scans\n# if left blank, all workload resources will be scanned\ntargetWorkloads: \"pod,replicaset,replicationcontroller,statefulset,daemonset,cronjob,job\"\n\n# -- nameOverride override operator name\nnameOverride: \"\"\n\n# -- fullnameOverride override operator full name\nfullnameOverride: \"trivy-operator\"\n\noperator:\n # -- namespace to install the operator, defaults to the .Release.Namespace\n namespace: \"\"\n # -- replicas the number of replicas of the operator's pod\n replicas: 1\n\n # -- number of old history to retain to allow rollback (if not set, default Kubernetes value is set to 10)\n revisionHistoryLimit: 5\n\n # -- additional annotations for the operator deployment\n annotations: {}\n\n # -- additional labels for the operator deployment\n labels: {}\n\n # -- additional labels for the operator pod\n podLabels:\n prometheus.deckhouse.io/custom-target: trivy-operator\n\n # -- leaderElectionId determines the name of the resource that leader election\n # will use for holding the leader lock.\n leaderElectionId: \"trivyoperator-lock\"\n\n # -- logDevMode the flag to enable development mode (more human-readable output, extra stack traces and logging information, etc)\n logDevMode: false\n\n # -- scanJobTTL the set automatic cleanup time after the job is completed\n scanJobTTL: \"\"\n\n # -- scanSecretTTL set an automatic cleanup for scan job secrets\n scanSecretTTL: \"\"\n\n # -- scanJobTimeout the length of time to wait before giving up on a scan job\n scanJobTimeout: 5m\n\n # -- scanJobsConcurrentLimit the maximum number of scan jobs create by the operator\n scanJobsConcurrentLimit: 5\n\n # -- scanNodeCollectorLimit the maximum number of node collector jobs create by the operator\n scanNodeCollectorLimit: 1\n\n # -- scanJobsRetryDelay the duration to wait before retrying a failed scan job\n scanJobsRetryDelay: 30s\n\n # -- the flag to enable vulnerability scanner\n vulnerabilityScannerEnabled: false\n # -- the flag to enable sbom generation, required for enabling ClusterVulnerabilityReports\n sbomGenerationEnabled: false\n # -- the flag to enable cluster sbom cache generation\n clusterSbomCacheEnabled: false\n # -- scannerReportTTL the flag to set how long a report should exist. \"\" means that the ScannerReportTTL feature is disabled\n scannerReportTTL: \"20h\"\n # -- cacheReportTTL the flag to set how long a cluster sbom report should exist. \"\" means that the cacheReportTTL feature is disabled\n cacheReportTTL: \"48h\"\n # -- configAuditScannerEnabled the flag to enable configuration audit scanner\n configAuditScannerEnabled: true\n # -- rbacAssessmentScannerEnabled the flag to enable rbac assessment scanner\n rbacAssessmentScannerEnabled: false\n # -- infraAssessmentScannerEnabled the flag to enable infra assessment scanner\n infraAssessmentScannerEnabled: true\n # -- clusterComplianceEnabled the flag to enable cluster compliance scanner\n clusterComplianceEnabled: true\n # -- batchDeleteLimit the maximum number of config audit reports deleted by the operator when the plugin's config has changed.\n batchDeleteLimit: 10\n # -- vulnerabilityScannerScanOnlyCurrentRevisions the flag to only create vulnerability scans on the current revision of a deployment.\n vulnerabilityScannerScanOnlyCurrentRevisions: false\n # -- configAuditScannerScanOnlyCurrentRevisions the flag to only create config audit scans on the current revision of a deployment.\n configAuditScannerScanOnlyCurrentRevisions: true\n # -- batchDeleteDelay the duration to wait before deleting another batch of config audit reports.\n batchDeleteDelay: 10s\n # -- accessGlobalSecretsAndServiceAccount The flag to enable access to global secrets/service accounts to allow `vulnerability scan job` to pull images from private registries\n accessGlobalSecretsAndServiceAccount: false\n # -- builtInTrivyServer The flag enables the usage of built-in trivy server in cluster. It also overrides the following trivy params with built-in values\n # trivy.mode = ClientServer and serverURL = http://<serverServiceName>.<trivy operator namespace>:4975\n builtInTrivyServer: false\n # -- builtInServerRegistryInsecure is the flag to enable insecure connection from the built-in Trivy server to the registry.\n builtInServerRegistryInsecure: false\n # -- controllerCacheSyncTimeout the duration to wait for controller resources cache sync (default: 5m).\n controllerCacheSyncTimeout: \"5m\"\n\n # -- trivyServerHealthCheckCacheExpiration The flag to set the interval for trivy server health cache before it invalidate\n trivyServerHealthCheckCacheExpiration: 10h\n\n # -- metricsFindingsEnabled the flag to enable metrics for findings\n metricsFindingsEnabled: true\n\n # -- metricsVulnIdEnabled the flag to enable metrics about cve vulns id\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsVulnIdEnabled: false\n\n # -- exposedSecretScannerEnabled the flag to enable exposed secret scanner\n exposedSecretScannerEnabled: false\n\n # -- MetricsExposedSecretInfo the flag to enable metrics about exposed secrets\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsExposedSecretInfo: false\n\n # -- MetricsConfigAuditInfo the flag to enable metrics about configuration audits\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsConfigAuditInfo: false\n\n # -- MetricsRbacAssessmentInfo the flag to enable metrics about Rbac Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsRbacAssessmentInfo: false\n\n # -- MetricsInfraAssessmentInfo the flag to enable metrics about Infra Assessment\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsInfraAssessmentInfo: false\n\n # -- MetricsImageInfo the flag to enable metrics about Image Information of scanned images\n # This information has image os information including os family, name/version, and if end of service life has been reached\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsImageInfo: false\n\n # -- MetricsClusterComplianceInfo the flag to enable metrics about Cluster Compliance\n # be aware of metrics cardinality is significantly increased with this feature enabled.\n metricsClusterComplianceInfo: true\n\n # -- serverAdditionalAnnotations the flag to set additional annotations for the trivy server pod\n serverAdditionalAnnotations: {}\n\n # -- webhookBroadcastURL the flag to set reports should be sent to a webhook endpoint. \"\" means that the webhookBroadcastURL feature is disabled\n webhookBroadcastURL: \"\"\n\n # -- webhookBroadcastTimeout the flag to set timeout for webhook requests if webhookBroadcastURL is enabled\n webhookBroadcastTimeout: 30s\n\n # -- webhookBroadcastCustomHeaders the flag to set webhook endpoint sent with custom defined headers if webhookBroadcastURL is enabled\n webhookBroadcastCustomHeaders: \"\"\n\n # -- webhookSendDeletedReports the flag to enable sending deleted reports if webhookBroadcastURL is enabled\n webhookSendDeletedReports: false\n\n # -- privateRegistryScanSecretsNames is map of namespace:secrets, secrets are comma seperated which can be used to authenticate in private registries in case if there no imagePullSecrets provided example : {\"mynamespace\":\"mySecrets,anotherSecret\"}\n privateRegistryScanSecretsNames: {}\n\n # -- mergeRbacFindingWithConfigAudit the flag to enable merging rbac finding with config-audit report\n mergeRbacFindingWithConfigAudit: false\n\n # -- httpProxy is the HTTP proxy used by Trivy operator to download the default policies from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy operator to download the default policies from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply OPERATOR_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply OPERATOR_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\nimage:\n registry: \"mirror.gcr.io\"\n repository: \"aquasec/trivy-operator\"\n # -- tag is an override of the image tag, which is by default set by the\n # appVersion field in Chart.yaml.\n tag: \"\"\n # -- pullPolicy set the operator pullPolicy\n pullPolicy: IfNotPresent\n # -- pullSecrets set the operator pullSecrets\n pullSecrets: []\n\n# -- service only expose a metrics endpoint for prometheus to scrape,\n# trivy-operator does not have a user interface.\nservice:\n # -- if true, the Service doesn't allocate any IP\n headless: false\n # -- port exposed by the Service\n metricsPort: 80\n # -- annotations added to the operator's service\n annotations: {}\n # -- appProtocol of the monitoring service\n metricsAppProtocol: TCP\n # -- the Service type\n type: ClusterIP\n # -- the nodeport to use when service type is LoadBalancer or NodePort. If not set, Kubernetes automatically select one.\n nodePort:\n\n # -- Prometheus ServiceMonitor configuration -- to install the trivy operator with the ServiceMonitor\n # you must have Prometheus already installed and running. If you do not have Prometheus installed, enabling this will\n # have no effect.\nserviceMonitor:\n # -- enabled determines whether a serviceMonitor should be deployed\n enabled: false\n # -- The namespace where Prometheus expects to find service monitors\n namespace: ~\n # -- Interval at which metrics should be scraped. If not specified Prometheus global scrape interval is used.\n interval: ~\n # -- Additional annotations for the serviceMonitor\n annotations: {}\n # -- Additional labels for the serviceMonitor\n labels: {}\n # -- HonorLabels chooses the metrics labels on collisions with target labels\n honorLabels: true\n # -- EndpointAdditionalProperties allows setting additional properties on the endpoint such as relabelings, metricRelabelings etc.\n endpointAdditionalProperties: {}\n\nreportMetrics:\n enabled: true\n image:\n registry: registry.k8s.io\n repository: kube-state-metrics\n tag: 2.18.0\n pullPolicy: IfNotPresent\n serviceAccount:\n create: true\n name: \"\"\n podAnnotations: {}\n podLabels: {}\n service:\n customTarget: custom-trivy-kube-state-metrics\n port: 8080\n path: /metrics\n sampleLimit: 15000\n resources:\n requests:\n cpu: 50m\n memory: 128Mi\n limits:\n cpu: 200m\n memory: 256Mi\n\ntrivyOperator:\n # -- vulnerabilityReportsPlugin the name of the plugin that generates vulnerability reports `Trivy`\n vulnerabilityReportsPlugin: \"Trivy\"\n # -- configAuditReportsPlugin the name of the plugin that generates config audit reports.\n configAuditReportsPlugin: \"Trivy\"\n # -- scanJobCompressLogs control whether scanjob output should be compressed or plain\n scanJobCompressLogs: false\n # -- scanJobAffinity affinity to be applied to the scanner pods and node-collector\n scanJobAffinity: {}\n # -- scanJobTolerations tolerations to be applied to the scanner pods so that they can run on nodes with matching taints\n scanJobTolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- scanJobNodeSelector nodeSelector to be applied to the scanner pods so that they can run on nodes with matching labels\n scanJobNodeSelector: {}\n # -- If you do want to specify nodeSelector, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobNodeSelector:'.\n # nodeType: worker\n # cpu: sandylake\n # teamOwner: operators\n\n # -- scanJobCustomVolumesMount add custom volumes mount to the scan job\n scanJobCustomVolumesMount: []\n # - name: var-lib-etcd\n # mountPath: /var/lib/etcd\n # readOnly: true\n\n # -- scanJobCustomVolumes add custom volumes to the scan job\n scanJobCustomVolumes: []\n # - name: var-lib-etcd\n # hostPath:\n # path: /var/lib/etcd\n\n # -- useGCRServiceAccount the flag to enable the usage of GCR service account for scanning images in GCR\n useGCRServiceAccount: true\n # -- scanJobAutomountServiceAccountToken the flag to enable automount for service account token on scan job\n scanJobAutomountServiceAccountToken: false\n\n # -- scanJobAnnotations comma-separated representation of the annotations which the user wants the scanner jobs and pods to be\n # annotated with. Example: `foo=bar,env=stage` will annotate the scanner jobs and pods with the annotations `foo: bar` and `env: stage`\n scanJobAnnotations: \"\"\n\n # -- scanJobPodTemplateLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the scanner pods with the labels `foo: bar` and `env: stage`\n scanJobPodTemplateLabels: \"\"\n\n # -- skipInitContainers when this flag is set to true, the initContainers will be skipped for the scanner and node collector pods\n skipInitContainers: false\n\n # -- scanJobPodTemplatePodSecurityContext podSecurityContext the user wants the scanner and node collector pods to be amended with.\n # Example:\n # RunAsUser: 10000\n # RunAsGroup: 10000\n # RunAsNonRoot: true\n scanJobPodTemplatePodSecurityContext: {}\n\n # -- scanJobPodTemplateContainerSecurityContext SecurityContext the user wants the scanner and node collector containers (and their\n # initContainers) to be amended with.\n scanJobPodTemplateContainerSecurityContext:\n allowPrivilegeEscalation: false\n capabilities:\n drop:\n - ALL\n privileged: false\n readOnlyRootFilesystem: true\n # -- For filesystem scanning, Trivy needs to run as the root user\n # runAsUser: 0\n\n # -- scanJobPodPriorityClassName Priority class name to be set on the pods created by trivy operator jobs. This accepts a string value\n scanJobPodPriorityClassName: \"\"\n\n # -- reportResourceLabels comma-separated scanned resource labels which the user wants to include in the Prometheus\n # metrics report. Example: `owner,app`\n reportResourceLabels: \"\"\n\n # -- reportRecordFailedChecksOnly flag is to record only failed checks on misconfiguration reports (config-audit and rbac assessment)\n reportRecordFailedChecksOnly: true\n\n # -- skipResourceByLabels comma-separated labels keys which trivy-operator will skip scanning on resources with matching labels\n skipResourceByLabels: \"\"\n\n # -- metricsResourceLabelsPrefix Prefix that will be prepended to the labels names indicated in `reportResourceLabels`\n # when including them in the Prometheus metrics\n metricsResourceLabelsPrefix: \"k8s_label_\"\n\n # -- additionalReportLabels comma-separated representation of the labels which the user wants the scanner pods to be\n # labeled with. Example: `foo=bar,env=stage` will labeled the reports with the labels `foo: bar` and `env: stage`\n additionalReportLabels: \"\"\n\n # -- policiesConfig Custom Rego Policies to be used by the config audit scanner\n # See https://github.com/aquasecurity/trivy-operator/blob/main/docs/tutorials/writing-custom-configuration-audit-policies.md for more details.\n policiesConfig: \"\"\n\n # -- excludeImages is comma separated glob patterns for excluding images from scanning.\n # Example: pattern: `k8s.gcr.io/*/*` will exclude image: `k8s.gcr.io/coredns/coredns:v1.8.0`.\n excludeImages: \"\"\n\ntrivy:\n # -- createConfig indicates whether to create config objects\n createConfig: true\n image:\n # -- registry of the Trivy image\n registry: mirror.gcr.io\n # -- repository of the Trivy image\n repository: aquasec/trivy\n # -- tag version of the Trivy image\n tag: 0.60.0\n # -- imagePullSecret is the secret name to be used when pulling trivy image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n\n # -- pullPolicy is the imge pull policy used for trivy image , valid values are (Always, Never, IfNotPresent)\n pullPolicy: IfNotPresent\n\n # -- mode is the Trivy client mode. Either Standalone or ClientServer. Depending\n # on the active mode other settings might be applicable or required.\n mode: Standalone\n\n # -- sbomSources trivy will try to retrieve SBOM from the specified sources (oci,rekor)\n sbomSources: \"\"\n\n # -- includeDevDeps include development dependencies in the report (supported: npm, yarn) (default: false)\n # note: this flag is only applicable when trivy.command is set to filesystem\n includeDevDeps: false\n\n # -- whether to use a storage class for trivy server or emptydir (one mey want to use ephemeral storage)\n storageClassEnabled: true\n\n # -- storageClassName is the name of the storage class to be used for trivy server PVC. If empty, tries to find default storage class\n storageClassName: \"\"\n\n # -- storageSize is the size of the trivy server PVC\n storageSize: \"5Gi\"\n\n # -- labels is the extra labels to be used for trivy server statefulset\n labels: {}\n\n # -- podLabels is the extra pod labels to be used for trivy server\n podLabels: {}\n\n # -- priorityClassName is the name of the priority class used for trivy server\n priorityClassName: \"\"\n\n # -- additionalVulnerabilityReportFields is a comma separated list of additional fields which\n # can be added to the VulnerabilityReport. Supported parameters: Description, Links, CVSS, Target, Class, PackagePath and PackageType\n additionalVulnerabilityReportFields: \"\"\n\n # -- httpProxy is the HTTP proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpProxy: ~\n\n # -- httpsProxy is the HTTPS proxy used by Trivy to download the vulnerabilities database from GitHub.\n httpsProxy: ~\n\n # -- noProxy is a comma separated list of IPs and domain names that are not subject to proxy settings.\n noProxy: ~\n\n # -- Registries without SSL. There can be multiple registries with different keys.\n nonSslRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- sslCertDir can be used to override the system default locations for SSL certificate files directory, example: /ssl/certs\n sslCertDir: ~\n\n # -- The registry to which insecure connections are allowed. There can be multiple registries with different keys.\n insecureRegistries: {}\n # pocRegistry: poc.myregistry.harbor.com.pl\n # qaRegistry: qa.registry.aquasec.com\n # internalRegistry: registry.registry.svc:5000\n\n # -- Mirrored registries. There can be multiple registries with different keys.\n # Make sure to quote registries containing dots\n registry:\n mirror: {}\n # \"docker.io\": docker-mirror.example.com\n\n # -- severity is a comma separated list of severity levels reported by Trivy.\n severity: UNKNOWN,HIGH,CRITICAL\n\n # -- slow this flag is to use less CPU/memory for scanning though it takes more time than normal scanning. It fits small-footprint\n slow: true\n # -- ignoreUnfixed is the flag to show only fixed vulnerabilities in\n # vulnerabilities reported by Trivy. Set to true to enable it.\n #\n ignoreUnfixed: true\n # -- a comma separated list of file paths for Trivy to skip\n skipFiles: # -- a comma separated list of directories for Trivy to skip\n\n skipDirs:\n\n # -- offlineScan is the flag to enable the offline scan functionality in Trivy\n # This will prevent outgoing HTTP requests, e.g. to search.maven.org\n offlineScan: false\n\n # -- timeout is the duration to wait for scan completion.\n timeout: \"5m0s\"\n\n # -- ignoreFile can be used to tell Trivy to ignore vulnerabilities by ID (one per line)\n ignoreFile: ~\n # ignoreFile:\n # - CVE-1970-0001\n # - CVE-1970-0002\n\n # -- ignorePolicy can be used to tell Trivy to ignore vulnerabilities by a policy\n # If multiple policies would match, then the most specific one has precedence over the others.\n # See https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#by-open-policy-agent for more details.\n # See https://github.com/aquasecurity/trivy/blob/v0.19.2/contrib/example_policy/basic.rego for more details on ignorePolicy filtering.\n #\n # ignorePolicy.application.my-app-.: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"application\" with the name pattern \"my-app-*\"\n # ignorePolicy.kube-system: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all workloads in namespace \"kube-system\"\n # ignorePolicy: |\n # package trivy\n\n # import data.lib.trivy\n\n # default ignore = true\n # applies to all other workloads\n\n # -- vulnType can be used to tell Trivy to filter vulnerabilities by a pkg-type (library, os)\n vulnType: ~\n\n # -- resources resource requests and limits for scan job containers\n resources:\n requests:\n cpu: 100m\n memory: 100M\n # ephemeralStorage: \"2Gi\"\n limits:\n cpu: 500m\n memory: 1Gi\n # ephemeralStorage: \"2Gi\"\n\n # -- githubToken is the GitHub access token used by Trivy to download the vulnerabilities\n # database from GitHub. Only applicable in Standalone mode.\n githubToken: ~\n\n # -- serverURL is the endpoint URL of the Trivy server. Required in ClientServer mode.\n #\n # serverURL: \"https://trivy.trivy:4975\"\n\n # -- clientServerSkipUpdate is the flag to enable skip databases update for Trivy client.\n # Only applicable in ClientServer mode.\n clientServerSkipUpdate: false\n\n # -- skipJavaDBUpdate is the flag to enable skip Java index databases update for Trivy client.\n skipJavaDBUpdate: false\n\n # -- serverInsecure is the flag to enable insecure connection to the Trivy server.\n serverInsecure: false\n\n # -- serverToken is the token to authenticate Trivy client with Trivy server. Only\n # applicable in ClientServer mode.\n serverToken: ~\n\n # -- existingSecret if a secret containing gitHubToken, serverToken or serverCustomHeaders has been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: trivy.githubToken, trivy.serverToken, trivy.serverCustomHeaders\n # Overrides trivy.gitHubToken, trivy.serverToken, trivy.serverCustomHeaders values.\n # Note: The secret has to be named \"trivy-operator-trivy-config\".\n # existingSecret: true\n\n # -- serverTokenHeader is the name of the HTTP header used to send the authentication\n # token to Trivy server. Only application in ClientServer mode when\n # trivy.serverToken is specified.\n serverTokenHeader: \"Trivy-Token\"\n\n # -- serverCustomHeaders is a comma separated list of custom HTTP headers sent by\n # Trivy client to Trivy server. Only applicable in ClientServer mode.\n serverCustomHeaders: ~\n # serverCustomHeaders: \"foo=bar\"\n\n dbRegistry: \"mirror.gcr.io\"\n dbRepository: \"aquasec/trivy-db\"\n\n # -- The username for dbRepository authentication\n #\n dbRepositoryUsername: ~\n\n # -- The password for dbRepository authentication\n #\n dbRepositoryPassword: ~\n\n # -- javaDbRegistry is the registry for the Java vulnerability database.\n javaDbRegistry: \"mirror.gcr.io\"\n javaDbRepository: \"aquasec/trivy-java-db\"\n\n # -- The Flag to enable insecure connection for downloading trivy-db via proxy (air-gaped env)\n #\n dbRepositoryInsecure: \"false\"\n\n # -- The Flag to enable the usage of builtin rego policies by default, these policies are downloaded by default from mirror.gcr.io/aquasec/trivy-checks\n #\n useBuiltinRegoPolicies: \"false\"\n # -- The Flag to enable the usage of external rego policies config-map, this should be used when the user wants to use their own rego policies\n #\n externalRegoPoliciesEnabled: false\n # -- To enable the usage of embedded rego policies, set the flag useEmbeddedRegoPolicies. This should serve as a fallback for air-gapped environments.\n # When useEmbeddedRegoPolicies is set to true, useBuiltinRegoPolicies should be set to false.\n useEmbeddedRegoPolicies: \"true\"\n\n # -- The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner\n #\n supportedConfigAuditKinds: \"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota\"\n\n # -- command. One of `image`, `filesystem` or `rootfs` scanning, depending on the target type required for the scan.\n # For 'filesystem' and `rootfs` scanning, ensure that the `trivyOperator.scanJobPodTemplateContainerSecurityContext` is configured\n # to run as the root user (runAsUser = 0).\n command: image\n # -- imageScanCacheDir the flag to set custom path for trivy image scan `cache-dir` parameter.\n # Only applicable in image scan mode.\n imageScanCacheDir: \"/tmp/trivy/.cache\"\n # -- filesystemScanCacheDir the flag to set custom path for trivy filesystem scan `cache-dir` parameter.\n # Only applicable in filesystem scan mode.\n filesystemScanCacheDir: \"/var/trivyoperator/trivy-db\"\n # -- serverUser this param is the server user to be used to download db from private registry\n serverUser: \"\"\n # -- serverPassword this param is the server user to be used to download db from private registry\n serverPassword: \"\"\n # -- serverServiceName this param is the server service name to be used in cluster\n serverServiceName: \"trivy-service\"\n # -- debug One of `true` or `false`. Enables debug mode.\n debug: false\n\n server:\n # -- resources set trivy-server resource\n resources:\n requests:\n cpu: 200m\n memory: 512Mi\n # ephemeral-storage: \"2Gi\"\n limits:\n cpu: 1\n memory: 1Gi\n # ephemeral-storage: \"2Gi\"\n\n # -- podSecurityContext set trivy-server podSecurityContext\n podSecurityContext:\n runAsUser: 65534\n runAsNonRoot: true\n fsGroup: 65534\n\n # -- securityContext set trivy-server securityContext\n securityContext:\n privileged: false\n readOnlyRootFilesystem: true\n\n # -- the number of replicas of the trivy-server\n replicas: 1\n\n # -- vaulesFromConfigMap name of a ConfigMap to apply TRIVY_* environment variables. Will override Helm values.\n valuesFromConfigMap: \"\"\n\n # -- valuesFromSecret name of a Secret to apply TRIVY_* environment variables. Will override Helm AND ConfigMap values.\n valuesFromSecret: \"\"\n\ncompliance:\n # -- failEntriesLimit the flag to limit the number of fail entries per control check in the cluster compliance detail report\n # this limit is for preventing the report from being too large per control checks\n failEntriesLimit: 10\n # -- reportType this flag control the type of report generated (summary or all)\n reportType: all\n # -- cron this flag control the cron interval for compliance report generation\n cron: 0 */6 * * *\n # -- specs is a list of compliance specs to be used by the cluster compliance scanner\n # - k8s-cis-1.23\n # - k8s-nsa-1.0\n # - k8s-pss-baseline-0.1\n # - k8s-pss-restricted-0.1\n # - eks-cis-1.4\n # - rke2-cis-1.24\n specs:\n - k8s-cis-1.23\n - k8s-nsa-1.0\n - k8s-pss-baseline-0.1\n - k8s-pss-restricted-0.1\n\nrbac:\n create: true\nserviceAccount:\n # -- Specifies whether a service account should be created.\n create: true\n annotations: {}\n # -- name specifies the name of the k8s Service Account. If not set and create is\n # true, a name is generated using the fullname template.\n name: \"\"\n\n# -- podAnnotations annotations added to the operator's pod\npodAnnotations:\n prometheus.deckhouse.io/port: \"8080\"\n\npodSecurityContext: {}\n# fsGroup: 2000\n\n# -- securityContext security context\nsecurityContext:\n privileged: false\n allowPrivilegeEscalation: false\n readOnlyRootFilesystem: true\n capabilities:\n drop:\n - ALL\n\nvolumeMounts:\n# do not remove , required for policies bundle\n- mountPath: /tmp\n name: cache-policies\n readOnly: false\n\nvolumes:\n# do not remove , required for policies bundle\n- name: cache-policies\n emptyDir: {}\n\nresources: {}\n# -- We usually recommend not to specify default resources and to leave this as a conscious\n# choice for the user. This also increases chances charts run on environments with little\n# resources, such as Minikube. If you do want to specify resources, uncomment the following\n# lines, adjust them as necessary, and remove the curly braces after 'resources:'.\n# limits:\n# cpu: 100m\n# memory: 128Mi\n# requests:\n# cpu: 100m\n# memory: 128Mi\n\n# -- nodeSelector set the operator nodeSelector\n#nodeSelector: {}\n\nnodeSelector:\n node-role.k8s.lmru.tech/application: ''\n\n# -- tolerations set the operator tolerations\ntolerations: []\n\n# -- affinity set the operator affinity\naffinity: {}\n\n# -- priorityClassName set the operator priorityClassName\npriorityClassName: \"\"\n\n# -- automountServiceAccountToken the flag to enable automount for service account token\nautomountServiceAccountToken: true\n\npoliciesBundle:\n # -- registry of the policies bundle\n registry: mirror.gcr.io\n # -- repository of the policies bundle\n repository: aquasec/trivy-checks\n # -- tag version of the policies bundle\n tag: 1\n # -- registryUser is the user for the registry\n registryUser: ~\n # -- registryPassword is the password for the registry\n registryPassword: ~\n # -- existingSecret if a secret containing registry credentials that have been created outside the chart (e.g external-secrets, sops, etc...).\n # Keys must be at least one of the following: policies.bundle.oci.user, policies.bundle.oci.password\n # Overrides policiesBundle.registryUser, policiesBundle.registryPassword values.\n # Note: The secret has to be named \"trivy-operator\".\n existingSecret: false\n # -- insecure is the flag to enable insecure connection to the policy bundle registry\n insecure: false\n\nnodeCollector:\n # -- useNodeSelector determine if to use nodeSelector (by auto detecting node name) with node-collector scan job\n useNodeSelector: false\n # -- registry of the node-collector image\n registry: docker-security.art.lmru.tech\n # -- repository of the node-collector image\n repository: aquasec/node-collector\n # -- tag version of the node-collector image\n tag: 0.3.1\n # -- imagePullSecret is the secret name to be used when pulling node-collector image from private registries example : reg-secret\n # It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace\n imagePullSecret: ~\n # -- excludeNodes comma-separated node labels that the node-collector job should exclude from scanning (example kubernetes.io/arch=arm64,team=dev)\n excludeNodes: # -- tolerations to be applied to the node-collector so that they can run on nodes with matching taints\n\n tolerations: []\n # -- If you do want to specify tolerations, uncomment the following lines, adjust them as necessary, and remove the\n # square brackets after 'scanJobTolerations:'.\n # - key: \"key1\"\n # operator: \"Equal\"\n # value: \"value1\"\n # effect: \"NoSchedule\"\n # -- node-collector pod volume mounts definition for collecting config files information\n volumeMounts:\n - name: var-lib-etcd\n mountPath: /var/lib/etcd\n readOnly: true\n - name: var-lib-kubelet\n mountPath: /var/lib/kubelet\n readOnly: true\n - name: var-lib-kube-scheduler\n mountPath: /var/lib/kube-scheduler\n readOnly: true\n - name: var-lib-kube-controller-manager\n mountPath: /var/lib/kube-controller-manager\n readOnly: true\n - name: etc-systemd\n mountPath: /etc/systemd\n readOnly: true\n - name: lib-systemd\n mountPath: /lib/systemd/\n readOnly: true\n - name: etc-kubernetes\n mountPath: /etc/kubernetes\n readOnly: true\n - name: etc-cni-netd\n mountPath: /etc/cni/net.d/\n readOnly: true\n # -- node-collector pod volumes definition for collecting config files information\n volumes:\n - name: var-lib-etcd\n hostPath:\n path: /var/lib/etcd\n - name: var-lib-kubelet\n hostPath:\n path: /var/lib/kubelet\n - name: var-lib-kube-scheduler\n hostPath:\n path: /var/lib/kube-scheduler\n - name: var-lib-kube-controller-manager\n hostPath:\n path: /var/lib/kube-controller-manager\n - name: etc-systemd\n hostPath:\n path: /etc/systemd\n - name: lib-systemd\n hostPath:\n path: /lib/systemd\n - name: etc-kubernetes\n hostPath:\n path: /etc/kubernetes\n - name: etc-cni-netd\n hostPath:\n path: /etc/cni/net.d/\n",
"firstEditBubbleId": "4ba51dd2-26c6-43df-b0c3-0041b1347745",
"isNewlyCreated": false,
"newlyCreatedFolders": []
},
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/templates/collector/configmap.yaml": {
"content": "{{- if .Values.reportMetrics.enabled }}\napiVersion: v1\nkind: ConfigMap\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\ndata:\n custom-resource-state.yaml: |\n kind: CustomResourceStateMetrics\n spec:\n resources:\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterComplianceReport\n metricNamePrefix: trivy_cluster_compliance\n labelsFromPath:\n name: [metadata, name]\n benchmark: [spec, compliance, title]\n benchmark_id: [spec, compliance, id]\n benchmark_type: [spec, compliance, type]\n benchmark_version: [spec, compliance, version]\n metrics:\n - name: pass_count\n help: Passed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, passCount]\n - name: fail_count\n help: Failed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, failCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - name: control_fail_total\n help: Failed checks per compliance control from Trivy ClusterComplianceReport summaryReport.\n each:\n type: Gauge\n gauge:\n path: [status, summaryReport, controlCheck]\n labelsFromPath:\n control_id: [id]\n control_name: [name]\n control_severity: [severity]\n valueFrom: [totalFail]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ConfigAuditReport\n metricNamePrefix: trivy_config_audit\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterConfigAuditReport\n metricNamePrefix: trivy_cluster_config_audit\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: InfraAssessmentReport\n metricNamePrefix: trivy_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterInfraAssessmentReport\n metricNamePrefix: trivy_cluster_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: VulnerabilityReport\n metricNamePrefix: trivy_vulnerability\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy VulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterVulnerabilityReport\n metricNamePrefix: trivy_cluster_vulnerability\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterVulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: RbacAssessmentReport\n metricNamePrefix: trivy_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy RbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterRbacAssessmentReport\n metricNamePrefix: trivy_cluster_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterRbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ExposedSecretReport\n metricNamePrefix: trivy_exposed_secret\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ExposedSecretReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: SbomReport\n metricNamePrefix: trivy_sbom\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy SbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterSbomReport\n metricNamePrefix: trivy_cluster_sbom\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterSbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n{{- end }}\n",
"firstEditBubbleId": "7aa728d5-677b-4e40-a8c6-0973c07e8b73",
"isNewlyCreated": false,
"newlyCreatedFolders": []
},
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/stage/templates/collector/deployment.yaml": {
"content": "{{- if .Values.reportMetrics.enabled }}\n{{- $registry := include \"global.imageRegistry\" . | default .Values.reportMetrics.image.registry }}\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\nspec:\n replicas: 1\n selector:\n matchLabels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 6 }}\n template:\n metadata:\n labels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 8 }}\n {{- with .Values.reportMetrics.podLabels }}\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.reportMetrics.podAnnotations }}\n annotations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n spec:\n serviceAccountName: {{ include \"trivy-operator.reportMetricsServiceAccountName\" . }}\n automountServiceAccountToken: true\n {{- with .Values.image.pullSecrets }}\n imagePullSecrets:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n securityContext:\n {{- toYaml .Values.podSecurityContext | nindent 8 }}\n containers:\n - name: kube-state-metrics\n image: \"{{ $registry }}/{{ .Values.reportMetrics.image.repository }}:{{ .Values.reportMetrics.image.tag }}\"\n imagePullPolicy: {{ .Values.reportMetrics.image.pullPolicy }}\n args:\n - --custom-resource-state-only=true\n - --use-apiserver-cache\n - --custom-resource-state-config-file=/etc/kube-state-metrics/custom-resource-state.yaml\n - --port={{ .Values.reportMetrics.service.port }}\n - --telemetry-port=8081\n ports:\n - name: metrics\n containerPort: {{ .Values.reportMetrics.service.port }}\n protocol: TCP\n - name: telemetry\n containerPort: 8081\n protocol: TCP\n livenessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 10\n readinessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 5\n resources:\n {{- toYaml .Values.reportMetrics.resources | nindent 12 }}\n securityContext:\n {{- toYaml .Values.securityContext | nindent 12 }}\n volumeMounts:\n - name: custom-resource-state\n mountPath: /etc/kube-state-metrics\n readOnly: true\n volumes:\n - name: custom-resource-state\n configMap:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n {{- with .Values.nodeSelector }}\n nodeSelector:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.affinity }}\n affinity:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.tolerations }}\n tolerations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n priorityClassName: {{ .Values.priorityClassName | quote }}\n{{- end }}\n",
"firstEditBubbleId": "08cfd30c-f9b4-4c39-b10a-bed5ddb11903",
"isNewlyCreated": false,
"newlyCreatedFolders": []
},
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/templates/collector/configmap.yaml": {
"content": "{{- if .Values.reportMetrics.enabled }}\napiVersion: v1\nkind: ConfigMap\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\ndata:\n custom-resource-state.yaml: |\n kind: CustomResourceStateMetrics\n spec:\n resources:\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterComplianceReport\n metricNamePrefix: trivy_cluster_compliance\n labelsFromPath:\n name: [metadata, name]\n benchmark: [spec, compliance, title]\n benchmark_id: [spec, compliance, id]\n benchmark_type: [spec, compliance, type]\n benchmark_version: [spec, compliance, version]\n metrics:\n - name: pass_count\n help: Passed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, passCount]\n - name: fail_count\n help: Failed checks reported by Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, summary, failCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [status, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterComplianceReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - name: control_fail_total\n help: Failed checks per compliance control from Trivy ClusterComplianceReport summaryReport.\n each:\n type: Gauge\n gauge:\n path: [status, summaryReport, controlCheck]\n labelsFromPath:\n control_id: [id]\n control_name: [name]\n control_severity: [severity]\n valueFrom: [totalFail]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ConfigAuditReport\n metricNamePrefix: trivy_config_audit\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterConfigAuditReport\n metricNamePrefix: trivy_cluster_config_audit\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: updated\n help: Last update timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [report, updateTimestamp]\n - name: created\n help: Creation timestamp for Trivy ClusterConfigAuditReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: InfraAssessmentReport\n metricNamePrefix: trivy_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy InfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterInfraAssessmentReport\n metricNamePrefix: trivy_cluster_infra_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n scanner: [report, scanner, name]\n scanner_vendor: [report, scanner, vendor]\n scanner_version: [report, scanner, version]\n metrics:\n - name: critical_count\n help: Critical findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, criticalCount]\n - name: high_count\n help: High findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, highCount]\n - name: medium_count\n help: Medium findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, mediumCount]\n - name: low_count\n help: Low findings reported by Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [report, summary, lowCount]\n - name: created\n help: Creation timestamp for Trivy ClusterInfraAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: VulnerabilityReport\n metricNamePrefix: trivy_vulnerability\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy VulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterVulnerabilityReport\n metricNamePrefix: trivy_cluster_vulnerability\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterVulnerabilityReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: RbacAssessmentReport\n metricNamePrefix: trivy_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy RbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterRbacAssessmentReport\n metricNamePrefix: trivy_cluster_rbac_assessment\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterRbacAssessmentReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ExposedSecretReport\n metricNamePrefix: trivy_exposed_secret\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ExposedSecretReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: SbomReport\n metricNamePrefix: trivy_sbom\n labelsFromPath:\n name: [metadata, name]\n exported_namespace: [metadata, namespace]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy SbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n - groupVersionKind:\n group: aquasecurity.github.io\n version: v1alpha1\n kind: ClusterSbomReport\n metricNamePrefix: trivy_cluster_sbom\n labelsFromPath:\n name: [metadata, name]\n resource_kind: [metadata, labels, \"trivy-operator.resource.kind\"]\n resource_name: [metadata, labels, \"trivy-operator.resource.name\"]\n metrics:\n - name: created\n help: Creation timestamp for Trivy ClusterSbomReport.\n each:\n type: Gauge\n gauge:\n path: [metadata, creationTimestamp]\n{{- end }}\n",
"firstEditBubbleId": "5ef06089-fe42-4f12-8319-8052af5eb445",
"isNewlyCreated": false,
"newlyCreatedFolders": []
},
"file:///home/ruslanpi/Documents/repos/lmru--devops--argocd-apps/common/trivy-operator/prod/templates/collector/deployment.yaml": {
"content": "{{- if .Values.reportMetrics.enabled }}\n{{- $registry := include \"global.imageRegistry\" . | default .Values.reportMetrics.image.registry }}\napiVersion: apps/v1\nkind: Deployment\nmetadata:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}\n namespace: {{ include \"trivy-operator.namespace\" . }}\n labels:\n {{- include \"trivy-operator.labels\" . | nindent 4 }}\n app.kubernetes.io/component: report-metrics\nspec:\n replicas: 1\n selector:\n matchLabels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 6 }}\n template:\n metadata:\n labels:\n {{- include \"trivy-operator.reportMetricsSelectorLabels\" . | nindent 8 }}\n {{- with .Values.reportMetrics.podLabels }}\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.reportMetrics.podAnnotations }}\n annotations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n spec:\n serviceAccountName: {{ include \"trivy-operator.reportMetricsServiceAccountName\" . }}\n automountServiceAccountToken: true\n {{- with .Values.image.pullSecrets }}\n imagePullSecrets:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n securityContext:\n {{- toYaml .Values.podSecurityContext | nindent 8 }}\n containers:\n - name: kube-state-metrics\n image: \"{{ $registry }}/{{ .Values.reportMetrics.image.repository }}:{{ .Values.reportMetrics.image.tag }}\"\n imagePullPolicy: {{ .Values.reportMetrics.image.pullPolicy }}\n args:\n - --custom-resource-state-only=true\n - --use-apiserver-cache\n - --custom-resource-state-config-file=/etc/kube-state-metrics/custom-resource-state.yaml\n - --port={{ .Values.reportMetrics.service.port }}\n - --telemetry-port=8081\n ports:\n - name: metrics\n containerPort: {{ .Values.reportMetrics.service.port }}\n protocol: TCP\n - name: telemetry\n containerPort: 8081\n protocol: TCP\n livenessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 10\n readinessProbe:\n httpGet:\n path: /healthz\n port: metrics\n initialDelaySeconds: 5\n resources:\n {{- toYaml .Values.reportMetrics.resources | nindent 12 }}\n securityContext:\n {{- toYaml .Values.securityContext | nindent 12 }}\n volumeMounts:\n - name: custom-resource-state\n mountPath: /etc/kube-state-metrics\n readOnly: true\n volumes:\n - name: custom-resource-state\n configMap:\n name: {{ include \"trivy-operator.reportMetricsName\" . }}-config\n {{- with .Values.nodeSelector }}\n nodeSelector:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.affinity }}\n affinity:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n {{- with .Values.tolerations }}\n tolerations:\n {{- toYaml . | nindent 8 }}\n {{- end }}\n priorityClassName: {{ .Values.priorityClassName | quote }}\n{{- end }}\n",
"firstEditBubbleId": "6448a3c1-9c6d-48d4-abe1-72a197c85fc0",
"isNewlyCreated": false,
"newlyCreatedFolders": []
}
},
"newlyCreatedFiles": [],
"newlyCreatedFolders": [],
"lastUpdatedAt": 1773313861707,
"createdAt": 1773308045531,
"hasChangedContext": true,
"activeTabsShouldBeReactive": true,
"capabilities": [
{
"type": 30,
"data": {}
},
{
"type": 15,
"data": {
"bubbleDataMap": "{}"
}
},
{
"type": 22,
"data": {}
},
{
"type": 18,
"data": {}
},
{
"type": 19,
"data": {}
},
{
"type": 33,
"data": {}
},
{
"type": 32,
"data": {}
},
{
"type": 23,
"data": {}
},
{
"type": 16,
"data": {}
},
{
"type": 24,
"data": {}
},
{
"type": 21,
"data": {}
},
{
"type": 31,
"data": {}
},
{
"type": 29,
"data": {}
}
],
"name": "Reading reports with filters",
"isFileListExpanded": false,
"browserChipManuallyDisabled": false,
"browserChipManuallyEnabled": false,
"unifiedMode": "agent",
"forceMode": "edit",
"usageData": {},
"contextUsagePercent": 84.74779411764706,
"contextTokensUsed": 230514,
"contextTokenLimit": 272000,
"allAttachedFileCodeChunksUris": [],
"modelConfig": {
"modelName": "premium",
"maxMode": false
},
"subComposerIds": [],
"subagentComposerIds": [],
"capabilityContexts": [],
"todos": [],
"isQueueExpanded": true,
"hasUnreadMessages": false,
"gitHubPromptDismissed": false,
"totalLinesAdded": 954,
"totalLinesRemoved": 736,
"addedFiles": 0,
"removedFiles": 0,
"isDraft": false,
"isCreatingWorktree": false,
"isApplyingWorktree": false,
"isUndoingWorktree": false,
"applied": false,
"pendingCreateWorktree": false,
"worktreeStartedReadOnly": false,
"isBestOfNSubcomposer": false,
"isBestOfNParent": false,
"bestOfNJudgeWinner": false,
"isSpec": false,
"isProject": false,
"isSpecSubagentDone": false,
"isContinuationInProgress": false,
"stopHookLoopCount": 0,
"committedToBranch": "DSO-102",
"createdOnBranch": "DSO-102",
"activeBranch": {
"branchName": "DSO-102",
"lastInteractionAt": 1773313745533
},
"branches": [
{
"branchName": "DSO-102",
"lastInteractionAt": 1773313745533
}
],
"speculativeSummarizationEncryptionKey": "Hr4qakxdBHW0C5jQmg8qhUobhg6EQrV3Zd2OcDdtVaM=",
"isNAL": true,
"agentBackend": "cursor-agent",
"planModeSuggestionUsed": false,
"debugModeSuggestionUsed": false,
"conversationState": "~CiDcNtNS/ttQPMUZhGkpqcqK0asra1BEUTyHkyWuovHEjwogHwywSrX93rRsMBFdJGjP7rjf2xpZDciEMVgSXRaxbOMKIEjrVSm9P7RCu1vc+xIm5lNTmggdDOczcZe2zyaHDnRqCiAEsZy84fg/owbGxQNknoRuwr4HW8VvtH9xVYWWt3/LWQoggYbrQenPy4pY7//zzuKoAsrpMyZof4Dl0oPM/x89FgQKINgTZu3JXJTz52tivD83AVyntWm1+1gbhkL2JqjlOs3fCiCnVdpZh+3v/fh3iAaCwitiihETO2/9qzAx26SDXXaTcAog+Jql55xI245aaPwcLgjnMF2om4U8PYOWeAUCnxFbKVkKIPuyKDif2EuHaTeyi+uhiO2woKedGY6bcDVvTyL8FrOhCiA+BrblfoFOtqTT8qOSNQ47MyDltlEAFmfTegzYGowSGgogp+2oqD+wxqSGWL8nbqamW12Radqt9+VDsuzaGKdZkBEKIPSG/LXjfOqSRy4rd+9j5obtoH5VN7JpV85IJ4ETbh7UCiBEe8ZN25U4tmxHCvs1Sz9Tky6q3GehjN1aY35Pdl9QewogdDnNUhMmV75Z7Q+lYAbk+zZoNyJvOS7bbAKmCUYWzA8KIM6ayiySGBYg9zE4FHi2MiUxA4/Xwh7vXyB//mAToeR7CiAfdxRKhZWJ7C35AWITsiP6gCYGwvI/P1yRkkp/vrc9BgogYlbQ70d3/g7Qp7Van2clwfwNKF8alycCND0smePnZ/gKIPCfX4e8f2GjCNNIm/p99qByr3hAxSHp0M7/M7LZxD/mCiBMbCJ0lofqnsGWA7rb+U4XdN61KMM9uveLN1YOcPr4SAog06aXsS2TVEOuV1H6zutYra0uGVhOdvyhE8b/pTRYH7oKIM4Ufiv9EjAbrCZLoAJidD7gDDroo9SNFS6HGBijQ3QLCiBaYwfj5MsCYAsVrHpv963kdK4GpvxLhM1QQISg8e/2LQog/TIu7OFAlLgGqfAa1NiKdyNTreoVmpMrY7ApyCbKE5YKIEtruDyumLAsekV09VWEGsaUaiiLnR5mFwhUFMP3Ke3ECiDerPpZIpSkwTlIAF7CUG0TzEdqPMw4knbLpNaXec0g2wogKePORsiuDl48VSsJ5H38dXPuADRcbBpy1MJAydEKfeMKIFKL57WF54ZSJhcw08PnnnkBtpEVm6neTbbNzMPcRkt2CiC2sCiuPEDOnR2xOxNgWtfFPFyawkYS3ugIwiJlEMZD0gogdxjWcdfcH3n2mi6o7axAhKoXdX0L0lGwP41CkDVJD5QKIBD6BQil+qEs6lLv8LFUqpM8Zfny5+LFHWrvrpQxO1KQCiCCbKnBO/69BDwRTP8vHPolyBZJpcmeEs98szfZFLgFgwogxyjdrUL2MvSadEycJGDvn1TkDJPoW2WHnLoQSEEnUHwKIFvikxlJIKYwNqY1cJw8Mw0Lxyg+6rN8FoaggH0F50k5CiA1UVC95fI1VpsM7QeMYDth65p8E3C8K2FFgWltpl+18gogXdM5JeZTc0oEsfefBUjkNIRNMIzlCGt/zHnnVIo0F/QKILRDR3vxq6vdLr/B/Tg94crr9EhdFJMLBgfbZ8fVjPTZCiDCUj9DpSI63bMJIux/iW4vbeu+4y/7tlWgDXlHXYvOTwogACPuUDjzG8tTgZqd8kxtRGiiLtf3kbvR0yAKtehvnEIKIKH9jan3/zSs1PMYRXY7dEl1xIrokRqgwMDU6jVMvwXUCiA0k6m3IqH4+jWI1nyv10RHgTDiI3vLhMiv6Qt+kDKbHAoghM3tEY70bifl2GNClsCjo2UvxQ5jHlrgDd6k8W3erxoKIIl20TN55DiSbCB3OouIl+GbpSrFHzxy9R/2XbzozBshCiDGJGXPJEFRxeZvK/5jdThVC1AIN4XrBspSJ4mZaaCfIgog9Pegw/lnIZ+X6+apO5QPBdnd/iCKswwfSBxcqMG45bMKIK4hCPkd1k0WN2fL16VeoyrmIbiwStHoGuVxyotnovpwCiCUWAQN5AYrw3GaCBia+M5r4T7AGuc9XLns7AT0o20Z4gog9BtvVMYTrK+k93odlOa2z5GRGpup6CEtVW6fOWA4bA8KIB7BMMGMtKVHlfMRiZ3p28j641rFDlOJQmTrJNeHGKLFCiCLu+Kti2mdhp6Bjfx/6fshpju/BsRbkkE2Jgx8XvhN0gogUylqgYf41ZLtVr4Anm5i+AlmptLz+vMwUPG0l9cVajgKII3txQ6a3AFvCJOo537pyhO+60IWoZbNi9liNw2dIyxxCiCfD4T3X80fi1EOr0dgR7ZF/23So40m1+ZvIpRpcw6iYAogsY3up9X+yMkvUPYXm9lQwDyLvo4jobBasITL1kmkX0QKIEdWJ4HuHephZlUSRWX8Q2J0s8r+L5NZ7g6jDRJk7QhGCiA9yaXWhETXVZWnUWs7Ts0/izn2VRJ4tAqRalon0566GAogHHQtzhBERlqa6RH6n+O+s3XKu25WGyFTrIxhH0Zd1YsKIKr8NK7JaOvtznWVGh08rJK8LyD/dqu+ZkeSTCu6+BbDCiADDA+mUzZDiEDMLlWv8RWoGfktwHgMrvChL4QtAE08TQogTLc+54ZxTxVkGdiziQRQ0RmrKoT7/4mItQY53r1Y6VYKICXnu7bTVqCB1A7nxHA3nJcIG1UG+Ap0yNqvRlac53wmCiDd/fVBJB9tjoKMGH03StIiFikwMlztDre2h8KG0hpcSQogYSXs77ABqeOEZkg3cU7uKt9axlhXywgdpMROM1zJjCUKIHi4DefWsPaFm0yuhTAsr4N35ARXCdkuYTzbhhp94MisCiAQjXFDMb6ou2o9ZxHyH1IYIhZ81iQgVPpPQ2OKKUxMWgog9GYkLnCeaOrm8t7Dzy8PNADzhTR14l/0TbDEAzwt23IKINxoyUkw/ecGaHMSKlzKm+ul5Qbih94aUrRqjmdz9xaDCiDnJoY38F/F3AHVOzJ4V5twyvVFhR4T4CbEgHTlMFH6MAogPTAedioC3+Xt0M35njIbgUakVXsKziz6kcCF0KWHpvsKIBYX2OFMFUkVsOX+653Z6B1Zsh0TuCfNYBaKGYtNce5+CiB/sMXmzS6G4h46xyTJk4/FRDlDcpTKVkshCZ6FGrN+cQogdBDxQlxDvxYgROBALEA84UEqIjmmdQP1CZhKMCd9dGoKICokc+hkJ+tqMw2xpmvtNUZY/4DuqOAnmErxgpAy2pFuCiBuBfBtUckza4HjGv3tOop/pXJvuVI1mDQtM6MrZuBxAAogmJL/w+T+5rTfLLTJDkD9IRVu/D5rhWziPuqNG4RJlggKIIgTwjJUvUHW9RZE4+XpgjbfTKRoLt/dShMyWaP7BKqCCiC2Aq/Dboa3Ne7oxmRZ8owTshJeLdjpOYKu6bGxJLRrAAogxDtTXRhJEUsqNAX61BozDvFJ6lmYfBIqvmsm0TzHcRgKIHz84b8JAe8sx2XqonU6e/KL0zrc3TkryhGfnXt3NBiVCiCz3EWw6kGZhrKopZg/gah4awQCxfH/Y9fVXaTUQKWCUAogIbGOizoHt/9bvXUhun78eZ3sidNvCMGEpKfGo8Y8Xu0KIMyaRNNTxwkmantTkwZT03ZDBTm1k2xUbp8j1n9/kMcZCiBRHZgX//4LsEH9zIyYAqIXNUZw+g6tWaxqf8LCvWoGGQogDPSeDOq2QI+LRjKmbUeBUumP2o5EzZSFPTvlQKAYMIkKIOhcEZ83y1N7LQEdchVtBZJaKREZAUXKNADqu3BqXnMfCiABlI+NnkG2Fa5ZYAwhnE4SQLjMX+B8iBucju7mp+7joAogY1SavHdD3q2hdVz1B7UIDdzUx2SYdiCBckSKh26wVwAKIBBAkmCf+D1dhVenF0RsdpJVP8NVQnks4S96kYGVB5DbCiAec/kR4F/J6p4r2/113oQizXQuQYsIwTLVFugONafDewogb6/cYj1TRicp5ygg1/3v9NDwoi4dFJy06vBPuzrZ9iEKIBUt7JqZSDZvDFByEVUtlCn2jgVoybCVTfWZKmWwP4POCiBxS+5/5vf8KCqsT7ZFeqnuuIBIIjEZJQHKn2CH4yop9gog30Ih2CtIJekWMmxdta0gLHKPk48eYq3m0mMYliWkTwIKID0UCcSPA1LWQkqHv8oa+6/qOnQj0HxVcCSPfZrEeF6TCiDYKDoTdQUQwyI8lZB4/K4d1biZdqzCKQbfvkKzzPUJdQog8rv+isiqiLyESY9Io+1DOUazhbgA0vqjN3enpGgmYv4KIMT4eGSdx4UPhqBgxNwcj/9/xhqjWFDvsPayohjvJPhDCiCs/nNpciCDW9FbUNtah5GKSQ1Zz+/tcE33n1t6Wm7xlwogg9Ug59GPu+dkxWBmfcxCO/A4GKnPlnUZDwHkxH5SsoYKIIC2cicFAhe9vzUW+bgg+PIu7dt/D9dMhd0T/3jOa164CiC0t7uc18jUJnsoZGp4/t2QJKVN6jnisrO9LkYeRtKpeQogeZdU+6/RFOEQuJindl5/a/Lg2Y2Uq+u0NJzhR24pFAUKIOaD+rDA2LF8Vm2OJFYJ2G6x6VSXKKJsGJ06qsEvasnbCiCVHKrYJQzu8paDcIW4OYM6mDLeKCrj+0mdrer7jfW68gog0Auv8PiMcyIvZgQiSj/TzV2Ya9f1hpDhaw7IHfI45x8KIM5vlf9BBr/rwRj6gW74LEJv4W85KAPFSTrRjdUiBJSWCiAKyYArRTomc5pNTy3k8x+JeaNJyKEIqtuR0CT0bjs8DwogVp+c1Y8DwWtVIF4diBP/7xnihvYLpPpOmNiITvvlddAKINt5ek3ySCFGm3rhhArxA66jFcIB+4o+g+TJ0OqiCmn3CiB/zCbljDeq0vv8RBFIGZwInF4ejH3U707GtXJ2Qq/BBwogcU8dtwzUzLpCOhCd0QzvMnEVl0UTN228o8zwWX+BY+sKIOvIo2kFQDdlNBWLHJGp/IP/VVpCAT/tGSCI0BbeelwTCiA057IsKYW1VKLLKjlm3CiRgtON6uPVlv3AtfShy7tqzgogaxhL8Q9HYNBgwoUceCbwZjX80gJV6opuveyariUHNsIKICp1i5RoCjC49YMNEZY3dIX1J2WY9+g1em5+cKeW2L+dCiAjMafTpIVqRQTOlWkswIUm6bw15tHESCU0AphliGWg7gogRBffpo7osSFS6Gd8/bSUOj+hZgJWcohmsgTIOTkZoDcKICL8rEIma9QSldWWigqUeGprYS5aHi/jqW/1TMEgQp0LCiBMYOxnpJWyIAIHZeW7ePqKPZhc5nIXm8V2rpacHiw18Qog2EqhM3NTBQii7Uo/wkoHsAlPRr8TI1Cin7JoCcT5oswKINyOGcthONWZZefROhDMU+rJT0tITQBiDAjCrKjnmmfdCiAKlNYjJPWtkeeCphFPctqJNaq2ODE8izdOJJYjufd9NwogvlcnZTS+Tvx4677vm94MmNt1Zm+lriX0pyXkr/X9ee0KIIRqK560FvFv8A1mRslHMs1KWISZsmH8HB2ZEyJj8CT9CiCi+1jS1iKAbpIHKKBmhS0QY4RoSXaZRAq0ORHM07mUZgog09yx2x7f4gqJqslnX5k3kfuXjaSUfgQCk3yL/5QW7LEKIIJX0XMs9sKzUHoAjzHocgDectIhQw3dYcOCb9b304fpCiBy6mQpK/0ZPNWA1O0rrM/Saru1l2a4tctTdxgfm4Mmfwog6qCjo4JuuVHHRiy6O2D9AxRyIcB/qsS+nIxTHBI2wisKIKDBQ2HD336YMYp0CyG1INILlr4sfBojVUvFL+0+EE9OCiDYyQK7Z+6HVdWUcNEX0vUiHsFH/gRhvuMwBddHXSMA1wogyd9jo4j2pKUe20JtnKYgOG71HXnuhNYG0q441Hh2NZ0KILfMdos2+VE4rvrMAc2SQ8C/M/DHvtPyl9i4OM/Cz9xHCiB3ImwiHxcDBisXNiIZ0x7igwzxZtzw8ypnMGzQxbj3lQogh8EDGd45u+s9QE4JeoBeCvkU8m0aQ3AGSwub8dwKnBEKINjB6ur5aCVFWCk/mqbuIPfJwBhkVI7IOhmMDXk+1TgHCiBvb5xVqnLhshepMfsn1OXF8zYk5EcMc/trLjXpsbhAjQogLWrzbvXZyMvo54kSYdb7l4DjHC0Yv4MDzQ9+ck/bpgsKIOYR/KwmMKeo7brQn+10aO/hUU0VER/Zho2eIY1FUF8GCiDUCK3rIc2FH4tOBPWm2QUuVvlQWzfIunu42wnWCXVB3AogUyhG+o/k/1Artuqt014dObrdPlDXhDXEVbUxpv+aS78KIKt3KrRgMpfQqykVz64Mgzoa2NcqhI88hDSExxop2gakCiDQ0nbz0IShUwvfQnZgqgm71RQ+rY9VkxlRqclxcLlRegogIz7B8eIykeXsDxIyITt9jzehwgmc+5ibq0PegyuR2RUKIJoH03W2U0h1Gxw37IC0KYM7bmkL7EuhszOm2InwrVisCiAxqdWJQPHUo7yNcnX2chVJvLW/0e+J+jf3nzr66ikupgogj+vuXSSqocKRxR9GDMroYoT8fMrUCw+wbwW4OMXNY1IKIM2flyOWw2kcyIlh2TAG8NmlbyKk2Uwb4pX30rDbfjplCiDB0bOpj4AGJX6DAgwKOf+Ho/R+44pfumujWQ5jFMUVUwogTzBdBBVZKFuL1q+y9091HqxbhzPq7WJW5q/8JBRHChQKIB+Cm1xUQm0om1IZITaO8ClTwhtdE0AeprZCi3k2gkYFCiBt2aHkbV34XS4WadBftVdZGIIVXLMYWj9mvZbr2sxESAogbl2GHmdwAZCxMomhEGnQCCByTqEA8dnPdUx2nAIOLVQKIHMtdDWSdqe6SkkJ9vjerNnuRToFJKnXC6/7hDmuauJLCiAKV4VLhTR5kuMNZb2fC+O+/aDsgfy5+MaZTIDrAI6ycgogsHe6X8JdKBGx1DF2GOxCsTcMOvno/Oj5FVYWZcr41aYKIEu1b3gOI3lM5VRUxlgxvAfURXeV0ZDxW852uWFcLz7wCiC5IP6pyzup25QOdjjYGKFVrD4D69YTyF3Lx/C1hgerZAog7RClSbQNBxP7dDrQOLfQYxh0yQAt9txQ0As49ghbUJsKILek8WqvWzGQx7vRQ4Y5zD4wY+W+QmwDMO6ZB/WO2NyrCiCl6QYdjKSjy4wneYHN51aEnL3KKPouA5fbXmfRCS2iPAogCgw0IvvLdD3kABFqll4yfpF2lQQbXAfFtcYJi4Rya0cKIHwtBclVebQjvuW7l3fXHMG1lX6vjI5GNDoulTP2bJKTCiDMl9TWJwhTDg7H3eXz1UYF27mM0IRSV127ajQqT+eLPwogZC65VD5D3fgG0W2Oj3OrXu4xq4cwTwU1uAOJj6v9KA4KIGrZGiMHEKkDfnawATXSM/N75xOkAmpPvnkgDCf/6d1jCiDYG52PubqGq/XYX0nW8mfgJl0zO+ThG/2V4D1WdV4EkQogOL6ObrKk8qG4fzWiNqZ4bS8vBn25l0G1rt0TX/IMo/MKIAnDtVbNTwiQeW1oNswwXE/fJueJDXveCYimtYmyd5c5CiDJBPKe+AZQU1R5mE8lr2P5LZriVv6d2ACvDg96Zar3qQog9q+82DUbeq1bXdrpIbC38Q8OlqWzHzqrUlQh5EVPGaIKID8J4YCbytb0VYJ40LfTQv8ww/nnmGADdSel3tsVi6TuCiBUw82rlwP46ajfOOybRoMQhWFjh3cw5nf5rVryCzDtAwogO2axYGyNOZ6oJumgjVd6enlp7PMwGRpW4RttMXJiKyoKIFGhuj+wl+KmDoeFUUCQwdAJnrumPHq+dySt7PdO50+yCiC7WFTzgXDnxeIoEUAAfLChThy49LndeDvYRktd3IyIpQogfm6fkHbr7lnssZLeCDr8xWhuKUV+vhR/fuYtfdXL+loKICNY2Vz6AS58jj/4Sl7fiyir+HTtk0HQRohyEVtOw0q3CiDA46h45jt5FDKZZknQUdAOnA1UX6aYt7Dc+1ABq/5/fAogGwOgCI/LcQ9xtphvfvqrVgX4/bsj+KWSRqa7XgBkfs4KIOukRLi9jTIlt/LZhBrYvzLg+kH1IVDeB0W0x7plM/oMCiDjZwXFDSa5d/eusiasrt44n5XkeCz6XRuyW+RVgc+Jhwog2AmNPRJYBgKm051PQyPmmLa8miYqDgiJCdaZbZhgKN8KIOJ+/9qGlSr3R75jrN54JGmvguT1g/ZOYKt0JdTD4CIiCiC5mVu5o83c1JnFwQVdKeY3kNs9UGZ2Ao3mRIU/UwF9TQogXH7D7omK2XozEO5UQON2hWq2SOpfeCXuzos2vx/h9N4KIGaUqGcdAQcgNeBsd3R5+L68uCD8zJHQvV/zzmgKtWQsCiBRMFYj0HwwrCvGoJlH1pHi22usF6k3ldwLYyRUTKPzMgogADvNJutHZmFZwcKC1BY4y4lf1Q6/MjMvkeFMmVLmVyIKIIPRP5/vQLnzxy9aqLPemScnswaBP+eOsNLidFQOqfNIKggI8ogOEIDNEEIgF+F8SyNn3PDMaAS5Fn1tJXYkJKhJWAim9dNbR1N04f5CIFjBsGEkIpIrmV1SeQ1L8rAaPt08cOeGsxf24p6vVX1CQiApucbE+OoBqsyQt5pSk3oFujMmdz9ORoONONKuB7eagEIg+12eLdsX/5Db6G8rCXWzZewBXXJAAuLli6EB67x3tXlCIFOrDvEMXj+A3KH8+ypXoNXJxeU4MZWKYzOq/iTwvjidQiBL4WiahZChuKXigMpNY3LT1km06pXEDgApoIJQWr6tW0IgaQs6gh9rwv6u3ckcV2hrqpGqFjboHb83vlmjem4wHJVCIOCvUF+CG0p1Bt4t9FBDsacBea+9Rwd0VPHAsu2ZL5YhQiChfoWIjs7ToLbNA3dpc+Rs+0DpEGUCPOBV+crUFoA3OUIgCIKmbLQc+DSRKO2bVj7ECXKXCNGwZDj0dzdk6Cu8pidCIKro+AUJRi4Xb3BIQVkM+tNQcK0R9kDqS4P4q+uBrNyUQiCx00Dk4DA3j9C3Fh9C14IGmcyQjkMHmQcOZ0DWk+pUa0Ig8Rdv9ULUXj0Pfb/6WXnG5kfm+B7b0v9uvSVFv/W6PEdCIGA4iyMSopgxd+AtuaGYqHZZWx+S8fgggv5K40TR+i4cSj9maWxlOi8vL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHNQAXq/AQp3L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvdGVtcGxhdGVzL2NvbGxlY3Rvci9kZXBsb3ltZW50LnlhbWwSRAog9+eHV9ASNObuOjZq6Z5vyTSy1Zn99/WEfXgoDH3RY0USIEcFDDbZk887RKvplSKd5VGiRCPY8KFRcDlwwayvxj6nesABCngvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9kZXBsb3ltZW50LnlhbWwSRAog9+eHV9ASNObuOjZq6Z5vyTSy1Zn99/WEfXgoDH3RY0USIEcFDDbZk887RKvplSKd5VGiRCPY8KFRcDlwwayvxj6ner4BCnYvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC90ZW1wbGF0ZXMvY29sbGVjdG9yL2NvbmZpZ21hcC55YW1sEkQKIHEnyLV4Al2DBWeXxR68sPK5rYR0XBD1Q5I4BeL+eonxEiBsfY+vGEDATL8kDO7f2oRahvpxaLSPO4bEizsZiLvkEXq/AQp3L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9jb2xsZWN0b3IvY29uZmlnbWFwLnlhbWwSRAogcSfItXgCXYMFZ5fFHryw8rmthHRcEPVDkjgF4v56ifESIGx9j68YQMBMvyQM7t/ahFqG+nFotI87hsSLOxmIu+QRerUBCm0vaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC92YWx1ZXMvdmFsdWVzLWdsb2JhbC55YW1sEkQKILgDRkBPUXGB3feGQDhVa01nZsgfY1e2BZmnY+0S7vcjEiA89dWffLt7WL/HnolskwdHewhNvADHZh0zwQecB6WS2Hq2AQpuL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3ZhbHVlcy92YWx1ZXMtZ2xvYmFsLnlhbWwSRAoguANGQE9RcYHd94ZAOFVrTWdmyB9jV7YFmadj7RLu9yMSIDz11Z98u3tYv8eeiWyTB0d7CE28AMdmHTPBB5wHpZLYkgF4L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL2Rhc2hib2FyZHMvdHJpdnktY3JkLWRhc2hib2FyZC5qc29ukgFlL2hvbWUvcnVzbGFucGkvLmN1cnNvci9wcm9qZWN0cy9ob21lLXJ1c2xhbnBpLURvY3VtZW50cy1yZXBvcy1sbXJ1LWRldm9wcy1hcmdvY2QtYXBwcy90ZXJtaW5hbHMvMS50eHSSAYABL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvZGFzaGJvYXJkcy90cml2eS1jcmQtZXhwbG9yZXItZGFzaGJvYXJkLmpzb26SAXkvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2dyYWZhbmEtY3JkLWRhc2hib2FyZC55YW1skgF4L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3Byb2QvdGVtcGxhdGVzL2dyYWZhbmEtY3JkLWRhc2hib2FyZC55YW1skgGBAS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS9kYXNoYm9hcmRzL3RyaXZ5LWNyZC1leHBsb3Jlci1kYXNoYm9hcmQuanNvbpIBdy9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL2NvbmZpZ21hcC55YW1skgFuL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3ZhbHVlcy92YWx1ZXMtZ2xvYmFsLnlhbWySAY4BL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL2NyZHMvYXF1YXNlY3VyaXR5LmdpdGh1Yi5pb19jbHVzdGVyY29tcGxpYW5jZXJlcG9ydHMueWFtbJIBigEvaG9tZS9ydXNsYW5waS8uY3Vyc29yL3Byb2plY3RzL2hvbWUtcnVzbGFucGktRG9jdW1lbnRzLXJlcG9zLWxtcnUtZGV2b3BzLWFyZ29jZC1hcHBzL2FnZW50LXRvb2xzL2IzYjgzNTk3LWI5MjgtNDdkOS1iMzM5LTM1MzA2ZGU5MGYyMi50eHSSAXkvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9jbHVzdGVycm9sZS55YW1skgF8L2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9jb2xsZWN0b3Ivc2VydmljZWFjY291bnQueWFtbJIBeC9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL2RlcGxveW1lbnQueWFtbJIBgAEvaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3Ivc3RhZ2UvdGVtcGxhdGVzL2NvbGxlY3Rvci9jbHVzdGVycm9sZWJpbmRpbmcueWFtbJIBdS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29sbGVjdG9yL3NlcnZpY2UueWFtbJIBdy9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29uZmlnbWFwcy9vcGVyYXRvci55YW1skgGEAS9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvY29uZmlnbWFwcy90cml2eS1vcGVyYXRvci1jb25maWcueWFtbJIBdi9ob21lL3J1c2xhbnBpL0RvY3VtZW50cy9yZXBvcy9sbXJ1LS1kZXZvcHMtLWFyZ29jZC1hcHBzL2NvbW1vbi90cml2eS1vcGVyYXRvci9zdGFnZS90ZW1wbGF0ZXMvc3BlY3MvazhzLWNpcy0xLjIzLnlhbWySAYoBL2hvbWUvcnVzbGFucGkvLmN1cnNvci9wcm9qZWN0cy9ob21lLXJ1c2xhbnBpLURvY3VtZW50cy1yZXBvcy1sbXJ1LWRldm9wcy1hcmdvY2QtYXBwcy9hZ2VudC10b29scy81MTZiYjdlOC1jZjUwLTQ2N2MtOWY4NC04MjZjNDdmNWMwYTkudHh0kgFrL2hvbWUvcnVzbGFucGkvRG9jdW1lbnRzL3JlcG9zL2xtcnUtLWRldm9wcy0tYXJnb2NkLWFwcHMvY29tbW9uL3RyaXZ5LW9wZXJhdG9yL3N0YWdlL3RlbXBsYXRlcy9faGVscGVycy50cGySAWovaG9tZS9ydXNsYW5waS9Eb2N1bWVudHMvcmVwb3MvbG1ydS0tZGV2b3BzLS1hcmdvY2QtYXBwcy9jb21tb24vdHJpdnktb3BlcmF0b3IvcHJvZC90ZW1wbGF0ZXMvX2hlbHBlcnMudHBs",
"queueItems": [],
"blobEncryptionKey": "ijf0mMgGI2Ar2LUlMY1QE0wmSfaq4VtoVhl/SH1geIQ=",
"latestChatGenerationUUID": "c8230c77-a958-4a9c-b5ec-4159eb2b4ab1",
"isAgentic": true,
"subtitle": "Edited deployment.yaml, deployment.yaml, values-global.yaml, configmap.yaml, values-global.yaml",
"filesChangedCount": 6
}