Loading cmd/felis/api.go +1 −0 Changes for cmd/felis/api.go: 1 added line, 0 removed lines. Original line number Diff line number Diff line Loading @@ -424,6 +424,7 @@ func buildConfig(cfg *config.Config) build.Config { // Empty keeps Trivy's own default; an install with builds points this at // the internal DB mirror (see config.RegistryConfig.TrivyDBRepository). TrivyDBRepository: cfg.Registry.TrivyDBRepository, TrivyJavaDBRepository: cfg.Registry.TrivyJavaDBRepository, } } Loading deploy/bootstrap.sh +1 −1 Changes for deploy/bootstrap.sh: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -2188,7 +2188,7 @@ persisted_registry_block() { out="$(awk ' /^[[:space:]]*\[/ { sect = $0; next } sect ~ /^[[:space:]]*\[registry\][[:space:]]*$/ && /^[[:space:]]*(kaniko_image|trivy_image|trivy_db_repository|build_cpu_limit|build_mem_limit|user_uploads_context)[[:space:]]*=/ { print } /^[[:space:]]*(kaniko_image|trivy_image|trivy_db_repository|trivy_java_db_repository|build_cpu_limit|build_mem_limit|user_uploads_context)[[:space:]]*=/ { print } sect ~ /^[[:space:]]*\[registry\.s3\][[:space:]]*$/ && /^[[:space:]]*[A-Za-z_]+[[:space:]]*=/ { if (!s3hdr) { printf "[registry.s3]\n"; s3hdr = 1 } print Loading deploy/bootstrap_test.sh +5 −0 Changes for deploy/bootstrap_test.sh: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -878,6 +878,7 @@ url = "stale.invalid:5000" build_namespace = "stale-ns" kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0" trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2" trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1" [registry.s3] endpoint = "https://s3.example" Loading Loading @@ -905,6 +906,10 @@ run_write "$rdir/out.toml" out="$(cat "$rdir/out.toml")" expect "a re-run carries the build-lane executor mirrors" \ 'kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0"' "$out" expect "a re-run carries the trivy vulnerability-DB mirror" \ 'trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2"' "$out" expect "a re-run carries the trivy java-DB mirror" \ 'trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1"' "$out" expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out" expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out" expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out" Loading docs/deferred-seams.md +6 −4 Changes for docs/deferred-seams.md: 6 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -57,10 +57,12 @@ A grep across `*.md` and `*.go` returns both sets; only the Go ones are seams. build_cpu_limit / build_mem_limit` override them for mirrored or air-gapped installs. Trivy's vulnerability DB is the same story, and now has its own knob: `[registry] trivy_db_repository` points `--db-repository` at an internal mirror (recipe in docs/troubleshooting.md §8e). Left unset on an egress-locked box the scan step fails closed — Kaniko pushes, Trivy exits on the DB download — which is the correct fail direction but leaves the build unfinished, so the mirror is part of a production build install. (recipe in docs/troubleshooting.md §8e); `trivy_java_db_repository` does the same for the Java DB, which Trivy fetches so soon as the scanned image contains a jar — i.e. for every real modpack build. Left unset on an egress-locked box the scan step fails closed — Kaniko pushes, Trivy exits on the DB download — which is the correct fail direction but leaves the build unfinished, so the mirrors are part of a production build install. ## Built; only its I/O is unverifiable from this repo Loading docs/troubleshooting.md +11 −0 Changes for docs/troubleshooting.md: 11 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -411,6 +411,7 @@ build_namespace = "felis-build" kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0" trivy_image = "registry.felis.svc:5000/mirror/trivy:0.74.0" trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2" trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1" build_cpu_limit = "2" build_mem_limit = "4Gi" ``` Loading @@ -423,10 +424,13 @@ through the loopback hostPort the registry Deployment binds (docker treats ```sh docker pull gcr.io/kaniko-project/executor:v1.24.0 # any versions you pin docker pull aquasec/trivy:0.74.0 docker pull mirror.gcr.io/aquasec/trivy-java-db:1 docker tag gcr.io/kaniko-project/executor:v1.24.0 127.0.0.1:5000/mirror/kaniko-executor:v1.24.0 docker tag aquasec/trivy:0.74.0 127.0.0.1:5000/mirror/trivy:0.74.0 docker tag mirror.gcr.io/aquasec/trivy-java-db:1 127.0.0.1:5000/mirror/trivy-java-db:1 docker push 127.0.0.1:5000/mirror/kaniko-executor:v1.24.0 docker push 127.0.0.1:5000/mirror/trivy:0.74.0 docker push 127.0.0.1:5000/mirror/trivy-java-db:1 ``` From another machine, port-forward the registry instead (`kubectl -n felis Loading Loading @@ -469,6 +473,13 @@ registry's plain HTTP works for the DB pull exactly as it does for the scanned image. Re-mirror the tag periodically (Trivy refreshes the DB several times a day upstream; a stale mirror only means stale CVE data, never a failed gate). `trivy_java_db_repository` is the same story one step lazier: Trivy downloads the Java DB on demand the first time it scans an image containing Java artifacts — every real modpack — and that download fails closed too. Mirror `mirror.gcr.io/aquasec/trivy-java-db:1` alongside the vulnerability DB (commands above); the Java DB refreshes far less often than the vulnerability DB, so a one-off mirror is usually fine. --- ## 9. Registry push/pull failures (spec §15) Loading Loading
cmd/felis/api.go +1 −0 Changes for cmd/felis/api.go: 1 added line, 0 removed lines. Original line number Diff line number Diff line Loading @@ -424,6 +424,7 @@ func buildConfig(cfg *config.Config) build.Config { // Empty keeps Trivy's own default; an install with builds points this at // the internal DB mirror (see config.RegistryConfig.TrivyDBRepository). TrivyDBRepository: cfg.Registry.TrivyDBRepository, TrivyJavaDBRepository: cfg.Registry.TrivyJavaDBRepository, } } Loading
deploy/bootstrap.sh +1 −1 Changes for deploy/bootstrap.sh: 1 added line, 1 removed line. Original line number Diff line number Diff line Loading @@ -2188,7 +2188,7 @@ persisted_registry_block() { out="$(awk ' /^[[:space:]]*\[/ { sect = $0; next } sect ~ /^[[:space:]]*\[registry\][[:space:]]*$/ && /^[[:space:]]*(kaniko_image|trivy_image|trivy_db_repository|build_cpu_limit|build_mem_limit|user_uploads_context)[[:space:]]*=/ { print } /^[[:space:]]*(kaniko_image|trivy_image|trivy_db_repository|trivy_java_db_repository|build_cpu_limit|build_mem_limit|user_uploads_context)[[:space:]]*=/ { print } sect ~ /^[[:space:]]*\[registry\.s3\][[:space:]]*$/ && /^[[:space:]]*[A-Za-z_]+[[:space:]]*=/ { if (!s3hdr) { printf "[registry.s3]\n"; s3hdr = 1 } print Loading
deploy/bootstrap_test.sh +5 −0 Changes for deploy/bootstrap_test.sh: 5 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -878,6 +878,7 @@ url = "stale.invalid:5000" build_namespace = "stale-ns" kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0" trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2" trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1" [registry.s3] endpoint = "https://s3.example" Loading Loading @@ -905,6 +906,10 @@ run_write "$rdir/out.toml" out="$(cat "$rdir/out.toml")" expect "a re-run carries the build-lane executor mirrors" \ 'kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0"' "$out" expect "a re-run carries the trivy vulnerability-DB mirror" \ 'trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2"' "$out" expect "a re-run carries the trivy java-DB mirror" \ 'trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1"' "$out" expect "a re-run carries the [registry.s3] uploads subtable" "[registry.s3]" "$out" expect "the carried subtable keeps its keys" 'endpoint = "https://s3.example"' "$out" expect "url stays installer-owned" 'url = "registry.felis.svc:5000"' "$out" Loading
docs/deferred-seams.md +6 −4 Changes for docs/deferred-seams.md: 6 added lines, 4 removed lines. Original line number Diff line number Diff line Loading @@ -57,10 +57,12 @@ A grep across `*.md` and `*.go` returns both sets; only the Go ones are seams. build_cpu_limit / build_mem_limit` override them for mirrored or air-gapped installs. Trivy's vulnerability DB is the same story, and now has its own knob: `[registry] trivy_db_repository` points `--db-repository` at an internal mirror (recipe in docs/troubleshooting.md §8e). Left unset on an egress-locked box the scan step fails closed — Kaniko pushes, Trivy exits on the DB download — which is the correct fail direction but leaves the build unfinished, so the mirror is part of a production build install. (recipe in docs/troubleshooting.md §8e); `trivy_java_db_repository` does the same for the Java DB, which Trivy fetches so soon as the scanned image contains a jar — i.e. for every real modpack build. Left unset on an egress-locked box the scan step fails closed — Kaniko pushes, Trivy exits on the DB download — which is the correct fail direction but leaves the build unfinished, so the mirrors are part of a production build install. ## Built; only its I/O is unverifiable from this repo Loading
docs/troubleshooting.md +11 −0 Changes for docs/troubleshooting.md: 11 added lines, 0 removed lines. Original line number Diff line number Diff line Loading @@ -411,6 +411,7 @@ build_namespace = "felis-build" kaniko_image = "registry.felis.svc:5000/mirror/kaniko-executor:v1.24.0" trivy_image = "registry.felis.svc:5000/mirror/trivy:0.74.0" trivy_db_repository = "registry.felis.svc:5000/mirror/trivy-db:2" trivy_java_db_repository = "registry.felis.svc:5000/mirror/trivy-java-db:1" build_cpu_limit = "2" build_mem_limit = "4Gi" ``` Loading @@ -423,10 +424,13 @@ through the loopback hostPort the registry Deployment binds (docker treats ```sh docker pull gcr.io/kaniko-project/executor:v1.24.0 # any versions you pin docker pull aquasec/trivy:0.74.0 docker pull mirror.gcr.io/aquasec/trivy-java-db:1 docker tag gcr.io/kaniko-project/executor:v1.24.0 127.0.0.1:5000/mirror/kaniko-executor:v1.24.0 docker tag aquasec/trivy:0.74.0 127.0.0.1:5000/mirror/trivy:0.74.0 docker tag mirror.gcr.io/aquasec/trivy-java-db:1 127.0.0.1:5000/mirror/trivy-java-db:1 docker push 127.0.0.1:5000/mirror/kaniko-executor:v1.24.0 docker push 127.0.0.1:5000/mirror/trivy:0.74.0 docker push 127.0.0.1:5000/mirror/trivy-java-db:1 ``` From another machine, port-forward the registry instead (`kubectl -n felis Loading Loading @@ -469,6 +473,13 @@ registry's plain HTTP works for the DB pull exactly as it does for the scanned image. Re-mirror the tag periodically (Trivy refreshes the DB several times a day upstream; a stale mirror only means stale CVE data, never a failed gate). `trivy_java_db_repository` is the same story one step lazier: Trivy downloads the Java DB on demand the first time it scans an image containing Java artifacts — every real modpack — and that download fails closed too. Mirror `mirror.gcr.io/aquasec/trivy-java-db:1` alongside the vulnerability DB (commands above); the Java DB refreshes far less often than the vulnerability DB, so a one-off mirror is usually fine. --- ## 9. Registry push/pull failures (spec §15) Loading