fix(build): mirror the Trivy Java DB — jar-bearing builds failed closed at the scan gate (#72)
This commit is contained in:
9 files changed
+77
-30
No files matched your search
+19
-13
@@ -225,6 +225,11 @@ type Config struct {
|
||||
// egress lock denies — an install with builds must point this at an internal
|
||||
// mirror (see config.RegistryConfig.TrivyDBRepository).
|
||||
TrivyDBRepository string
|
||||
// TrivyJavaDBRepository overrides where Trivy fetches its Java DB
|
||||
// (--java-db-repository), downloaded lazily for images that contain Java
|
||||
// artifacts — i.e. every real modpack. Same egress story as the
|
||||
// vulnerability DB (see config.RegistryConfig.TrivyJavaDBRepository).
|
||||
TrivyJavaDBRepository string
|
||||
// KanikoImage / TrivyImage are the executor images.
|
||||
KanikoImage string
|
||||
TrivyImage string
|
||||
@@ -359,19 +364,20 @@ func (b *Builder) Submit(ctx context.Context, req Request) (*Build, error) {
|
||||
// jobParams projects a build + config onto the inputs jobspec.go renders.
|
||||
func (b *Builder) jobParams(bld *Build, cfg Config) JobParams {
|
||||
return JobParams{
|
||||
BuildID: bld.ID,
|
||||
ImageRef: bld.ImageRef,
|
||||
ContextRef: bld.ContextRef,
|
||||
Namespace: cfg.Namespace,
|
||||
ServiceAccount: cfg.ServiceAccount,
|
||||
RegistryURL: cfg.RegistryURL,
|
||||
FelisImage: cfg.FelisImage,
|
||||
TrivyDBRepository: cfg.TrivyDBRepository,
|
||||
KanikoImage: cfg.KanikoImage,
|
||||
TrivyImage: cfg.TrivyImage,
|
||||
Deadline: cfg.Deadline,
|
||||
CPULimit: cfg.CPULimit,
|
||||
MemLimit: cfg.MemLimit,
|
||||
BuildID: bld.ID,
|
||||
ImageRef: bld.ImageRef,
|
||||
ContextRef: bld.ContextRef,
|
||||
Namespace: cfg.Namespace,
|
||||
ServiceAccount: cfg.ServiceAccount,
|
||||
RegistryURL: cfg.RegistryURL,
|
||||
FelisImage: cfg.FelisImage,
|
||||
TrivyDBRepository: cfg.TrivyDBRepository,
|
||||
TrivyJavaDBRepository: cfg.TrivyJavaDBRepository,
|
||||
KanikoImage: cfg.KanikoImage,
|
||||
TrivyImage: cfg.TrivyImage,
|
||||
Deadline: cfg.Deadline,
|
||||
CPULimit: cfg.CPULimit,
|
||||
MemLimit: cfg.MemLimit,
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -82,11 +82,16 @@ type JobParams struct {
|
||||
// --db-repository flag). Empty keeps Trivy's own default; see
|
||||
// build.Config.TrivyDBRepository for why an in-cluster install sets it.
|
||||
TrivyDBRepository string
|
||||
KanikoImage string
|
||||
TrivyImage string
|
||||
Deadline time.Duration
|
||||
CPULimit string
|
||||
MemLimit string
|
||||
// TrivyJavaDBRepository overrides Trivy's Java-DB source (the
|
||||
// --java-db-repository flag), fetched lazily when the image contains Java
|
||||
// artifacts; empty keeps Trivy's own default, which the build egress lock
|
||||
// denies — a jar-bearing image then fails the scan.
|
||||
TrivyJavaDBRepository string
|
||||
KanikoImage string
|
||||
TrivyImage string
|
||||
Deadline time.Duration
|
||||
CPULimit string
|
||||
MemLimit string
|
||||
}
|
||||
|
||||
// BuildJobName is the deterministic Job name for a build id.
|
||||
@@ -257,6 +262,9 @@ func BuildJob(p JobParams) (*batchv1.Job, error) {
|
||||
if p.TrivyDBRepository != "" {
|
||||
trivyArgs = append(trivyArgs, "--db-repository", p.TrivyDBRepository)
|
||||
}
|
||||
if p.TrivyJavaDBRepository != "" {
|
||||
trivyArgs = append(trivyArgs, "--java-db-repository", p.TrivyJavaDBRepository)
|
||||
}
|
||||
trivyArgs = append(trivyArgs, p.ImageRef)
|
||||
trivy := corev1.Container{
|
||||
Name: ContainerTrivy,
|
||||
|
||||
@@ -204,9 +204,9 @@ func TestBuildJobKanikoPushesAndTrivyGates(t *testing.T) {
|
||||
if !hasArg(trivy.Args, p.ImageRef) {
|
||||
t.Errorf("trivy must scan the pushed ref %q, args=%v", p.ImageRef, trivy.Args)
|
||||
}
|
||||
// No DB repository configured: Trivy keeps its own default.
|
||||
if hasArg(trivy.Args, "--db-repository") {
|
||||
t.Errorf("unset TrivyDBRepository must not render --db-repository, args=%v", trivy.Args)
|
||||
// No DB repositories configured: Trivy keeps its own defaults.
|
||||
if hasArg(trivy.Args, "--db-repository") || hasArg(trivy.Args, "--java-db-repository") {
|
||||
t.Errorf("unset DB repositories must not render --db-repository/--java-db-repository, args=%v", trivy.Args)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -262,12 +262,14 @@ func TestBuildJobKanikoGetsOnlyUnpackCapabilities(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// A configured DB repository (the internal mirror) must reach Trivy as
|
||||
// --db-repository: without it the scan tries the internet, which the build egress
|
||||
// lock denies, and every build fails closed at the scan gate.
|
||||
// Configured DB repositories (the internal mirrors) must reach Trivy as
|
||||
// --db-repository / --java-db-repository: without them the scan tries the
|
||||
// internet, which the build egress lock denies, and every build fails closed at
|
||||
// the scan gate — the Java DB the moment the image contains a jar.
|
||||
func TestBuildJobTrivyDBRepositoryOverride(t *testing.T) {
|
||||
p := sampleJobParams()
|
||||
p.TrivyDBRepository = "registry.felis.svc:5000/mirror/trivy-db:2"
|
||||
p.TrivyJavaDBRepository = "registry.felis.svc:5000/mirror/trivy-java-db:1"
|
||||
job, err := BuildJob(p)
|
||||
if err != nil {
|
||||
t.Fatalf("BuildJob: %v", err)
|
||||
@@ -276,6 +278,9 @@ func TestBuildJobTrivyDBRepositoryOverride(t *testing.T) {
|
||||
if !argPairPresent(trivy.Args, "--db-repository", p.TrivyDBRepository) {
|
||||
t.Errorf("trivy args = %v, want --db-repository %s", trivy.Args, p.TrivyDBRepository)
|
||||
}
|
||||
if !argPairPresent(trivy.Args, "--java-db-repository", p.TrivyJavaDBRepository) {
|
||||
t.Errorf("trivy args = %v, want --java-db-repository %s", trivy.Args, p.TrivyJavaDBRepository)
|
||||
}
|
||||
// The scanned image ref must stay the last argument.
|
||||
if last := trivy.Args[len(trivy.Args)-1]; last != p.ImageRef {
|
||||
t.Errorf("image ref must remain the last argument, args=%v", trivy.Args)
|
||||
|
||||
@@ -145,6 +145,15 @@ type RegistryConfig struct {
|
||||
// default (only usable on an install that deliberately opens internet
|
||||
// egress to the DB hosts).
|
||||
TrivyDBRepository string `toml:"trivy_db_repository"`
|
||||
// TrivyJavaDBRepository points Trivy at an OCI repository holding the Java
|
||||
// DB (--java-db-repository). Trivy fetches it lazily whenever the scanned
|
||||
// image contains Java artifacts — every real modpack image does — so on an
|
||||
// egress-locked box the scan fails closed without this mirror exactly like
|
||||
// the vulnerability DB. The supported shape is an internal mirror: copy
|
||||
// mirror.gcr.io/aquasec/trivy-java-db:1 into this cluster's registry and
|
||||
// set this to registry.<ns>.svc:5000/mirror/trivy-java-db:1 (recipe in
|
||||
// docs/troubleshooting.md §8e). Empty keeps Trivy's own default.
|
||||
TrivyJavaDBRepository string `toml:"trivy_java_db_repository"`
|
||||
// UserUploadsContext is the object-store base under which a user-submitted
|
||||
// modpack's Kaniko build context is pinned. It belongs to the §16 build
|
||||
// subsystem's input domain (the build-context store), introduced by the
|
||||
|
||||
Reference in new issue
Block a user