kyvernoReporter update to 2.16.0-bb.6
Status | Pipeline | Created by | Stages | |
---|---|---|---|---|
Passed 00:31:10
| Stage: 🎛 prevar Stage: 🔥 smoke tests |
Download artifacts
No artifacts found |
UNCLASSIFIED - NO CUI
Currently supported Big Bang Version is 2.49
Attention Iron Bank Customers: On March 27, 2025, we are moving SBOM artifacts from the Anchore Scan job to the Build job to streamline the container hardening pipeline. If you currently download SBOMs from the Anchore Scan job, you can still get them from the Build job and from other sources, including IBFE and image attestations.
This package MR includes a default value modification in kyverno-reporter/chart/values.yaml
to disable API token auto-mounting for the kyverno-reporter
ServiceAccount.
This essentially means that Pods leveraging the kyverno-reporter
ServiceAccount, by default, will not have access to their Kubernetes API token (previously mounted at /var/run/secrets/kubernetes.io/serviceaccount/token
).
Since this package deals with the Kubernetes API heavily - the kyverno-reporter
Pod overrides this behavior at the Pod spec-level here. As such, a Kyverno policy exception will be made for this Pod.
This is in support of epic &146.
big-bang/product/packages/kyverno-reporter!42 (merged)
and
big-bang/product/packages/kyverno-reporter!41 (merged) (skip-bb-mr
was used for this MR, since it just exposed some necessary values for the next MR)
Closes https://repo1.dso.mil/big-bang/product/packages/kyverno-reporter/-/issues/27
Status | Pipeline | Created by | Stages | |
---|---|---|---|---|
Passed 00:31:10
| Stage: 🎛 prevar Stage: 🔥 smoke tests |
Download artifacts
No artifacts found |
UNCLASSIFIED - NO CUI