Attention Iron Bank Customers: On March 27, 2025, we are moving SBOM artifacts from the Anchore Scan job to the Build job to streamline the container hardening pipeline. If you currently download SBOMs from the Anchore Scan job, you can still get them from the Build job and from other sources, including IBFE and image attestations.
After asking about the inconsistency I found out that coder was in fact considered a 3rd party app, so the scope of this ticket is to relocate it to it's correct location https://repo1.dso.mil/platform-one/big-bang/apps/third-party to clearly identify it as such.
Edited
Designs
Child items
0
Show closed items
No child items are currently assigned. Use child items to break down this issue into smaller parts.
Linked items
0
Link issues together to show that they're related or that one is blocking others.
Learn more.
While working on air gap I noticed that the repositories.tar.gz is missing redis and coder. (We do have an airgap customer using coder, I'm sure they came up with their own means of deploying coder so probably low priority for them.)
There's a few BB packages that use redis as a subchart, I'm not sure if that means it's embedded directly into the other repos or if the subchart is accessed as a remote call. If it's embedded directly, then redis wouldn't need to be added. (I need to get further into airgap quickstart to test this.)
It was also mentioned that coder might be a 3rd party app, if so it shouldn't be added, but if so it's also in the wrong location, because it's organized under developer tools and not 3rd party.
Micah Nagel confirmed on MM that there's no need to bundle redis
MicahN:
"Redis should work because we run a helm dependency update chart to bundle the subcharts as .tgz packages in the repo. We ran into that issue with airgap a while back and have been bundling the subcharts ever since. Shouldn't be anything else needed but we can add if there is."
Micah N also confirmed that Coder was supposed to move to 3rd party tools, (which would mean it's not supposed to go in repositories.tar.gz), he thought a ticket existed, but since one doesn't I'll repurpose this one.
I'll update the title from "Add coder and redis git repos to the repositories.tar.gz bundle available on releases page" to "Move coder from developer tools to 3rd party apps"
Christopher McGrathchanged title from Add coder and redis git repos to the repositories.tar.gz bundle available on releases page to Move coder from developer tools to 3rd party apps
changed title from Add coder and redis git repos to the repositories.tar.gz bundle available on releases page to Move coder from developer tools to 3rd party apps
I don't know who actually has the perms, but assigning to Ryan/Michael for now. I think with a redirect in place it shouldn't break any existing users but definitely good to let them know ahead of time.
As discussed at the Big Bang Product/Integration Sync, given the limited redirects supported, it is best to save this move for the BB 2.0 repo refactor.
@cmcgrath this issue has been inactive for 60 days and is being labelled as marked-for-auto-close. If this issue is still required please take action by removing the stale and marked-for-auto-close labels and commenting with an update, status, or justification. If this issue is not required please close it or label it as delete-me. If no action is taken this issue will be auto closed in 30 days.