Skip to content
This repository has been archived by the owner on Apr 30, 2021. It is now read-only.

Trivy deployment should support private Container Registries #203

Open
v1r7u opened this issue Apr 16, 2020 · 2 comments
Open

Trivy deployment should support private Container Registries #203

v1r7u opened this issue Apr 16, 2020 · 2 comments
Labels
kind/enhancement New feature or request lifecycle/backlog General backlog pile. Any idea, which could be taken into work priority/medium Medium priority issues size/S

Comments

@v1r7u
Copy link
Contributor

v1r7u commented Apr 16, 2020

Trivy scanner could scan images from private registries. To achieve that, it uses credentials from scanner configuration file.

At the moment of writing deployment scripts do not provide a way to add Container Registry credentials to this config file.

@v1r7u v1r7u added this to the v2 milestone Apr 16, 2020
@savas-guven savas-guven added kind/enhancement New feature or request priority/low Low priority issues labels Apr 28, 2020
@savas-guven
Copy link

I set this initially to Pri-3, but need to understand the marketplace and likelihood of private registries being in demand.

@v1r7u v1r7u added lifecycle/backlog General backlog pile. Any idea, which could be taken into work and removed priority/low Low priority issues labels May 5, 2020
@v1r7u v1r7u removed this from the v2 milestone May 5, 2020
@v1r7u
Copy link
Contributor Author

v1r7u commented May 5, 2020

I think it's next to impossible to find a k8s cluster without containers from a private registry. Once you build your application, it should be pushed to a location, which is accessible from the k8s cluster, but not visible to untrusted users - a private container-registry

@v1r7u v1r7u added size/S priority/high Top priority issues priority/medium Medium priority issues and removed priority/high Top priority issues labels May 5, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
kind/enhancement New feature or request lifecycle/backlog General backlog pile. Any idea, which could be taken into work priority/medium Medium priority issues size/S
Projects
None yet
Development

No branches or pull requests

2 participants