Please make an External Data provider for Gatekeeper #4354
Closed
tspearconquest
started this conversation in
Ideas
Replies: 3 comments
-
Hi there, so I understand you are using Gatekeeper, and looking to prevent vulnerable images from being admitted to the cluster correct?
|
Beta Was this translation helpful? Give feedback.
0 replies
-
Sure, I'm on there. I will ping to discuss. |
Beta Was this translation helpful? Give feedback.
0 replies
-
Closing as this is currently out of scope for Trivy scanner. Feel free to keep discussing if needed |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
I was looking into a recently added feature in the OPA Gatekeeper project wherein Gatekeeper can consume data from external sources in order to validate or mutate Kubernetes cluster resources.
https://open-policy-agent.github.io/gatekeeper/website/docs/externaldata
The external data comes from a Provider resource, which consumes the data from an HTTP endpoint (can be in cluster or external) and uses that data when reviewing a kubernetes resource for admission control purposes.
Some example providers are able to be found online (such as the example Trivy provider) but they are simply examples for end users/teams to follow in order to implement their own providers, and not intended for production use.
This feature request is opened to request an official Trivy external data provider supported by Aqua Security which can be used to prevent images with vulnerabilities from being admitted into a cluster.
This does not need to be open source, nor does it need to be free (as in beer) -- In fact, currently we only use the open source Trivy project, but I believe I could convince my organization into paying for the Aqua platform if this were offered as part of the platform.
Beta Was this translation helpful? Give feedback.
All reactions