UNCLASSIFIED - NO CUI
Attention Iron Bank Customers: On March 27, 2025, we are moving SBOM artifacts from the Anchore Scan job to the Build job to streamline the container hardening pipeline. If you currently download SBOMs from the Anchore Scan job, you can still get them from the Build job and from other sources, including IBFE and image attestations.
Using upstream recommended template to exclude resources to exlude all istio-init
containers from require-non-root-group ClusterPolicy
https://kyverno.io/docs/writing-policies/exceptions/
Also disabling wait-for-ready
job as I tried several settings to tune the job but doesn't seem to provide much use anymore.
Relates #43 (closed) #51 (closed)
UNCLASSIFIED - NO CUI