fix(build): mirror the Trivy Java DB — jar-bearing builds failed closed at the scan gate (#72)

This commit is contained in:
Lemon-miaow committed 2026-09-24 03:11:01 +08:00
1 parent 6e47730501
commit b14bacbfc6
9 files changed
+77 -30

No files matched your search

+19 -13
View File
@@ -225,6 +225,11 @@ type Config struct {
// egress lock denies — an install with builds must point this at an internal
// mirror (see config.RegistryConfig.TrivyDBRepository).
TrivyDBRepository string
// TrivyJavaDBRepository overrides where Trivy fetches its Java DB
// (--java-db-repository), downloaded lazily for images that contain Java
// artifacts — i.e. every real modpack. Same egress story as the
// vulnerability DB (see config.RegistryConfig.TrivyJavaDBRepository).
TrivyJavaDBRepository string
// KanikoImage / TrivyImage are the executor images.
KanikoImage string
TrivyImage string
@@ -359,19 +364,20 @@ func (b *Builder) Submit(ctx context.Context, req Request) (*Build, error) {
// jobParams projects a build + config onto the inputs jobspec.go renders.
func (b *Builder) jobParams(bld *Build, cfg Config) JobParams {
return JobParams{
BuildID: bld.ID,
ImageRef: bld.ImageRef,
ContextRef: bld.ContextRef,
Namespace: cfg.Namespace,
ServiceAccount: cfg.ServiceAccount,
RegistryURL: cfg.RegistryURL,
FelisImage: cfg.FelisImage,
TrivyDBRepository: cfg.TrivyDBRepository,
KanikoImage: cfg.KanikoImage,
TrivyImage: cfg.TrivyImage,
Deadline: cfg.Deadline,
CPULimit: cfg.CPULimit,
MemLimit: cfg.MemLimit,
BuildID: bld.ID,
ImageRef: bld.ImageRef,
ContextRef: bld.ContextRef,
Namespace: cfg.Namespace,
ServiceAccount: cfg.ServiceAccount,
RegistryURL: cfg.RegistryURL,
FelisImage: cfg.FelisImage,
TrivyDBRepository: cfg.TrivyDBRepository,
TrivyJavaDBRepository: cfg.TrivyJavaDBRepository,
KanikoImage: cfg.KanikoImage,
TrivyImage: cfg.TrivyImage,
Deadline: cfg.Deadline,
CPULimit: cfg.CPULimit,
MemLimit: cfg.MemLimit,
}
}
+13 -5
View File
@@ -82,11 +82,16 @@ type JobParams struct {
// --db-repository flag). Empty keeps Trivy's own default; see
// build.Config.TrivyDBRepository for why an in-cluster install sets it.
TrivyDBRepository string
KanikoImage string
TrivyImage string
Deadline time.Duration
CPULimit string
MemLimit string
// TrivyJavaDBRepository overrides Trivy's Java-DB source (the
// --java-db-repository flag), fetched lazily when the image contains Java
// artifacts; empty keeps Trivy's own default, which the build egress lock
// denies — a jar-bearing image then fails the scan.
TrivyJavaDBRepository string
KanikoImage string
TrivyImage string
Deadline time.Duration
CPULimit string
MemLimit string
}
// BuildJobName is the deterministic Job name for a build id.
@@ -257,6 +262,9 @@ func BuildJob(p JobParams) (*batchv1.Job, error) {
if p.TrivyDBRepository != "" {
trivyArgs = append(trivyArgs, "--db-repository", p.TrivyDBRepository)
}
if p.TrivyJavaDBRepository != "" {
trivyArgs = append(trivyArgs, "--java-db-repository", p.TrivyJavaDBRepository)
}
trivyArgs = append(trivyArgs, p.ImageRef)
trivy := corev1.Container{
Name: ContainerTrivy,
+11 -6
View File
@@ -204,9 +204,9 @@ func TestBuildJobKanikoPushesAndTrivyGates(t *testing.T) {
if !hasArg(trivy.Args, p.ImageRef) {
t.Errorf("trivy must scan the pushed ref %q, args=%v", p.ImageRef, trivy.Args)
}
// No DB repository configured: Trivy keeps its own default.
if hasArg(trivy.Args, "--db-repository") {
t.Errorf("unset TrivyDBRepository must not render --db-repository, args=%v", trivy.Args)
// No DB repositories configured: Trivy keeps its own defaults.
if hasArg(trivy.Args, "--db-repository") || hasArg(trivy.Args, "--java-db-repository") {
t.Errorf("unset DB repositories must not render --db-repository/--java-db-repository, args=%v", trivy.Args)
}
}
@@ -262,12 +262,14 @@ func TestBuildJobKanikoGetsOnlyUnpackCapabilities(t *testing.T) {
}
}
// A configured DB repository (the internal mirror) must reach Trivy as
// --db-repository: without it the scan tries the internet, which the build egress
// lock denies, and every build fails closed at the scan gate.
// Configured DB repositories (the internal mirrors) must reach Trivy as
// --db-repository / --java-db-repository: without them the scan tries the
// internet, which the build egress lock denies, and every build fails closed at
// the scan gate — the Java DB the moment the image contains a jar.
func TestBuildJobTrivyDBRepositoryOverride(t *testing.T) {
p := sampleJobParams()
p.TrivyDBRepository = "registry.felis.svc:5000/mirror/trivy-db:2"
p.TrivyJavaDBRepository = "registry.felis.svc:5000/mirror/trivy-java-db:1"
job, err := BuildJob(p)
if err != nil {
t.Fatalf("BuildJob: %v", err)
@@ -276,6 +278,9 @@ func TestBuildJobTrivyDBRepositoryOverride(t *testing.T) {
if !argPairPresent(trivy.Args, "--db-repository", p.TrivyDBRepository) {
t.Errorf("trivy args = %v, want --db-repository %s", trivy.Args, p.TrivyDBRepository)
}
if !argPairPresent(trivy.Args, "--java-db-repository", p.TrivyJavaDBRepository) {
t.Errorf("trivy args = %v, want --java-db-repository %s", trivy.Args, p.TrivyJavaDBRepository)
}
// The scanned image ref must stay the last argument.
if last := trivy.Args[len(trivy.Args)-1]; last != p.ImageRef {
t.Errorf("image ref must remain the last argument, args=%v", trivy.Args)
+9
View File
@@ -145,6 +145,15 @@ type RegistryConfig struct {
// default (only usable on an install that deliberately opens internet
// egress to the DB hosts).
TrivyDBRepository string `toml:"trivy_db_repository"`
// TrivyJavaDBRepository points Trivy at an OCI repository holding the Java
// DB (--java-db-repository). Trivy fetches it lazily whenever the scanned
// image contains Java artifacts — every real modpack image does — so on an
// egress-locked box the scan fails closed without this mirror exactly like
// the vulnerability DB. The supported shape is an internal mirror: copy
// mirror.gcr.io/aquasec/trivy-java-db:1 into this cluster's registry and
// set this to registry.<ns>.svc:5000/mirror/trivy-java-db:1 (recipe in
// docs/troubleshooting.md §8e). Empty keeps Trivy's own default.
TrivyJavaDBRepository string `toml:"trivy_java_db_repository"`
// UserUploadsContext is the object-store base under which a user-submitted
// modpack's Kaniko build context is pinned. It belongs to the §16 build
// subsystem's input domain (the build-context store), introduced by the