-
Notifications
You must be signed in to change notification settings - Fork 6.8k
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Is your feature request related to a problem?
Deploying trivy alongside argocd can result in non-trivial increase in RAM usage for application-controller pods.
This can incur extra costs or stability issues (application-controller pod has no default resources specified).
Case of this being an issue: https://cloud-native.slack.com/archives/C01TSERG0KZ/p1760521753256809
Related helm chart
argo-cd
Describe the solution you'd like
Include trivy CRDs into defaults for configs.cm."resource.exclusions":
- apiGroups:
- aquasecurity.github.io
kinds:
- ClusterComplianceReport
- ClusterConfigAuditReport
- ClusterInfraAssessmentReport
- ClusterRbacAssessmentReport
- ClusterSbomReport
- ClusterVulnerabilityReport
- ConfigAuditReport
- ExposedSecretReport
- InfraAssessmentReport
- RbacAssessmentReport
- SbomReport
- VulnerabilityReport
These objects are created and managed by Trivy operator and I don't see a reason why argo should watch them.
Describe alternatives you've considered
No response
Additional context
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request