This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grype](https://github.com/anchore/grype) | minor | `0.92.2` → `0.118.0` | --- ### Release Notes <details> <summary>anchore/grype (grype)</summary> ### [`v0.118.0`](https://github.com/anchore/grype/releases/tag/v0.118.0) ##### Added Features - apk matcher does alias aware aggregation \[PR [#​3634](https://github.com/anchore/grype/pull/3634) [@​crosleyzack](https://github.com/crosleyzack)] ##### Bug Fixes - prevent panic on portage versions without digits \[PR [#​3655](https://github.com/anchore/grype/pull/3655) [@​ashvinctrl](https://github.com/ashvinctrl)] - grype vex does not match oci purl with repository\_url \[Issue [#​3657](https://github.com/anchore/grype/issues/3657)] \[PR [#​3659](https://github.com/anchore/grype/pull/3659) [@​spiffcs](https://github.com/spiffcs)] - Old JVM version comparisons sometimes incorrect \[Issue [#​2701](https://github.com/anchore/grype/issues/2701)] \[PR [#​3583](https://github.com/anchore/grype/pull/3583) [@​Eljees](https://github.com/Eljees)] - CVSSv4 calculation can produce incorrect vulnerability severity \[Issue [#​3656](https://github.com/anchore/grype/issues/3656)] - Grype 0.90.0 DB update failed \[Issue [#​3629](https://github.com/anchore/grype/issues/3629)] ##### Dependencies 72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated. **🟢 Remediated (3)** - [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835) (Medium) — go.opentelemetry.io/otel - [GO-2026-6179](https://go.dev/issue/80744) (High) — golang.org/x/mod - [GO-2026-6180](https://go.dev/issue/80745) (High) — golang.org/x/mod <details> <summary>Updated (70 packages)</summary> - cel.dev/expr `v0.25.1` → `v0.25.2` - cloud.google.com/go/auth `v0.18.2` → `v0.22.0` - cloud.google.com/go/iam `v1.5.3` → `v1.11.0` - cloud.google.com/go/logging `v1.13.1` → `v1.18.0` - cloud.google.com/go/longrunning `v0.8.0` → `v1.2.0` - cloud.google.com/go/monitoring `v1.24.3` → `v1.29.0` - cloud.google.com/go/storage `v1.61.3` → `v1.64.0` - cloud.google.com/go/trace `v1.11.7` → `v1.16.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.32.0` → `v1.33.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping `v0.55.0` → `v0.57.0` - github.com/anchore/stereoscope `v0.3.0` → `v0.3.1` - github.com/anchore/syft `v1.51.0` → `v1.51.1` - github.com/aws/aws-sdk-go-v2 `v1.41.5` → `v1.43.4` - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream `v1.7.8` → `v1.7.16` - github.com/aws/aws-sdk-go-v2/config `v1.32.12` → `v1.32.35` - github.com/aws/aws-sdk-go-v2/credentials `v1.19.12` → `v1.19.34` - github.com/aws/aws-sdk-go-v2/feature/ec2/imds `v1.18.20` → `v1.18.35` - github.com/aws/aws-sdk-go-v2/internal/configsources `v1.4.21` → `v1.4.35` - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 `v2.7.21` → `v2.7.35` - github.com/aws/aws-sdk-go-v2/internal/v4a `v1.4.22` → `v1.4.36` - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding `v1.13.7` → `v1.13.15` - github.com/aws/aws-sdk-go-v2/service/internal/checksum `v1.9.13` → `v1.9.28` - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url `v1.13.21` → `v1.13.35` - github.com/aws/aws-sdk-go-v2/service/internal/s3shared `v1.19.21` → `v1.19.36` - github.com/aws/aws-sdk-go-v2/service/s3 `v1.97.3` → `v1.106.5` - github.com/aws/aws-sdk-go-v2/service/signin `v1.0.8` → `v1.5.4` - github.com/aws/aws-sdk-go-v2/service/sso `v1.30.13` → `v1.33.4` - github.com/aws/aws-sdk-go-v2/service/ssooidc `v1.35.17` → `v1.38.4` - github.com/aws/aws-sdk-go-v2/service/sts `v1.41.9` → `v1.45.4` - github.com/aws/smithy-go `v1.24.2` → `v1.27.6` - github.com/containerd/containerd/v2 `v2.3.3` → `v2.3.4` - github.com/containerd/platforms `v1.0.0-rc.4` → `v1.0.0-rc.5` - github.com/docker/cli `v29.6.1+incompatible` → `v29.7.2+incompatible` - github.com/docker/go-connections `v0.7.0` → `v0.8.1` - github.com/fatih/color `v1.18.0` → `v1.19.0` - github.com/google/go-containerregistry `v0.21.7` → `v0.21.9` - github.com/google/pprof `v0.0.0-6e76a2b` → `v0.0.0-ef3492d` - github.com/googleapis/enterprise-certificate-proxy `v0.3.14` → `v0.3.19` - github.com/googleapis/gax-go/v2 `v2.17.0` → `v2.23.0` - github.com/hashicorp/aws-sdk-go-base/v2 `v2.0.0-beta.72` → `v2.0.0-beta.74` - github.com/hashicorp/go-getter `v1.8.6` → `v1.8.8` - github.com/hashicorp/go-version `v1.8.0` → `v1.9.0` - github.com/klauspost/compress `v1.19.1` → `v1.19.2` - github.com/mattn/go-isatty `v0.0.20` → `v0.0.24` - github.com/moby/moby/client `v0.5.0` → `v0.5.1` - github.com/spiffe/go-spiffe/v2 `v2.6.0` → `v2.7.0` - github.com/stretchr/objx `v0.5.2` → `v0.5.3` - github.com/stretchr/testify `v1.11.1` → `v1.12.1` - go.opentelemetry.io/contrib/detectors/gcp `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel `v1.43.0` → `v1.44.0` **(🟢 remediated [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835))** - go.opentelemetry.io/otel/exporters/stdout/stdoutmetric `v1.40.0` → `v1.44.0` - go.opentelemetry.io/otel/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/trace `v1.43.0` → `v1.44.0` - golang.org/x/crypto `v0.54.0` → `v0.55.0` - golang.org/x/mod `v0.38.0` → `v0.40.0` **(🟢 remediated [GO-2026-6179](https://go.dev/issue/80744), [GO-2026-6180](https://go.dev/issue/80745))** - golang.org/x/net `v0.57.0` → `v0.58.0` - golang.org/x/text `v0.40.0` → `v0.41.0` - golang.org/x/tools `v0.48.0` → `v0.49.0` - google.golang.org/api `v0.271.0` → `v0.292.0` - google.golang.org/genproto `v0.0.0-8636f87` → `v0.0.0-aa98bba` - google.golang.org/genproto/googleapis/api `v0.0.0-afd174a` → `v0.0.0-925bb5d` - google.golang.org/genproto/googleapis/rpc `v0.0.0-afd174a` → `v0.0.0-6ac0973` - google.golang.org/grpc `v1.82.1` → `v1.83.0` - modernc.org/cc/v4 `v4.29.0` → `v4.29.1` - modernc.org/libc `v1.74.1` → `v1.74.4` - modernc.org/sqlite `v1.55.0` → `v1.56.0` </details> <details> <summary>Added (1 package)</summary> - go.opentelemetry.io/otel/metric/x `v0.66.0` </details> <details> <summary>Removed (1 package)</summary> - github.com/aws/aws-sdk-go-v2/internal/ini `v1.8.6` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.117.0...v0.118.0)** ### [`v0.117.0`](https://github.com/anchore/grype/releases/tag/v0.117.0) ##### Added Features - Include vulnerable ranges in CycloneDX output format \[Issue [#​3512](https://github.com/anchore/grype/issues/3512)] \[PR [#​3519](https://github.com/anchore/grype/pull/3519) [@​somaz94](https://github.com/somaz94)] ##### Bug Fixes - honor match.rust.using-cpes configuration \[PR [#​3611](https://github.com/anchore/grype/pull/3611) [@​Dashtid](https://github.com/Dashtid)] ##### Dependencies 11 dependency changes (11 updated). 2 vulnerabilities remediated. **🟢 Remediated (2)** - [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5 - [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5 <details> <summary>Updated (11 packages)</summary> - github.com/anchore/syft `v1.50.0` → `v1.51.0` - github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4` - github.com/gabriel-vasile/mimetype `v1.4.13` → `v1.4.15` - github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1` - github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))** - github.com/klauspost/compress `v1.19.0` → `v1.19.1` - github.com/magiconair/properties `v1.8.10` → `v1.18.11` - github.com/santhosh-tekuri/jsonschema/v6 `v6.0.2` → `v6.0.3` - github.com/ulikunitz/xz `v0.5.15` → `v0.5.16` - go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5` - modernc.org/sqlite `v1.54.0` → `v1.55.0` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.1...v0.117.0)** ### [`v0.116.1`](https://github.com/anchore/grype/releases/tag/v0.116.1) ##### Bug Fixes - Ensure channel parsing is consistent \[PR [#​3603](https://github.com/anchore/grype/pull/3603) [@​wagoodman](https://github.com/wagoodman)] - Scope Go GHSA twins by shared CVE \[PR [#​3592](https://github.com/anchore/grype/pull/3592) [@​wagoodman](https://github.com/wagoodman)] - do not cache a comparator that failed to build \[PR [#​3567](https://github.com/anchore/grype/pull/3567) [@​arpitjain099](https://github.com/arpitjain099)] - Add fix date to rhel minor records created from rhsa \[PR [#​3585](https://github.com/anchore/grype/pull/3585) [@​wagoodman](https://github.com/wagoodman)] - grype reporting CVE-64091 as critical - redhat says it is not affected \[Issue [#​3591](https://github.com/anchore/grype/issues/3591)] - panic: index out of range in distro.parseVersion for VERSION\_ID=v \[Issue [#​3588](https://github.com/anchore/grype/issues/3588)] \[PR [#​3589](https://github.com/anchore/grype/pull/3589) [@​matiasinsaurralde](https://github.com/matiasinsaurralde)] - False Positive: GO-2026-5932 \[Issue [#​3573](https://github.com/anchore/grype/issues/3573)] ##### Dependencies 30 dependency changes (30 updated). 1 vulnerability remediated. **🟢 Remediated (1)** - [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc <details> <summary>Updated (30 packages)</summary> - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0` - github.com/anchore/stereoscope `v0.2.2` → `v0.3.0` - github.com/anchore/syft `v1.48.0` → `v1.50.0` - github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58` - github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3` - github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible` - github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0` - github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3` - github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23` - github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0` - github.com/moby/moby/api `v1.54.2` → `v1.55.0` - github.com/moby/moby/client `v0.4.1` → `v0.5.0` - github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3` - go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0` - golang.org/x/crypto `v0.53.0` → `v0.54.0` - golang.org/x/mod `v0.37.0` → `v0.38.0` - golang.org/x/net `v0.56.0` → `v0.57.0` - golang.org/x/sync `v0.21.0` → `v0.22.0` - golang.org/x/sys `v0.46.0` → `v0.47.0` - golang.org/x/term `v0.44.0` → `v0.45.0` - golang.org/x/text `v0.39.0` → `v0.40.0` - golang.org/x/tools `v0.47.0` → `v0.48.0` - google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a` - google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a` - google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))** - modernc.org/cc/v4 `v4.28.4` → `v4.29.0` - modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6` - modernc.org/gc/v3 `v3.1.3` → `v3.1.4` - modernc.org/libc `v1.73.4` → `v1.74.1` - modernc.org/sqlite `v1.53.0` → `v1.54.0` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.0...v0.116.1)** ### [`v0.115.0`](https://github.com/anchore/grype/releases/tag/v0.115.0) ##### Added Features - emit golang.org/x/net vulns from govlundb \[PR [#​3534](https://github.com/anchore/grype/pull/3534) [@​willmurphyscode](https://github.com/willmurphyscode)] - Merge Go vuln matches with GHSA matches \[Issue [#​3515](https://github.com/anchore/grype/issues/3515)] ##### Bug Fixes - only emit records for stdlib \[PR [#​3527](https://github.com/anchore/grype/pull/3527) [@​willmurphyscode](https://github.com/willmurphyscode)] - mark hummingbird distro as rolling \[PR [#​3521](https://github.com/anchore/grype/pull/3521) [@​willmurphyscode](https://github.com/willmurphyscode)] - disable go stdlib CPE matching by default \[PR [#​3517](https://github.com/anchore/grype/pull/3517) [@​willmurphyscode](https://github.com/willmurphyscode)] - merge in custom ranges when applicable \[PR [#​3514](https://github.com/anchore/grype/pull/3514) [@​willmurphyscode](https://github.com/willmurphyscode)] - exclude linux-kbuild deb indirect matches by default \[PR [#​3506](https://github.com/anchore/grype/pull/3506) [@​westonsteimel](https://github.com/westonsteimel)] - avoid panic on invalid RHEL version IDs \[PR [#​3490](https://github.com/anchore/grype/pull/3490) [@​jspilman](https://github.com/jspilman)] - Support reading CycloneDX 1.7 SBOMs \[Issue [#​3373](https://github.com/anchore/grype/issues/3373)] - Grype cannot read mariadb version correctly \[Issue [#​3452](https://github.com/anchore/grype/issues/3452)] - grype hangs when downloading certain images using registry client \[Issue [#​3492](https://github.com/anchore/grype/issues/3492)] - Can we get a fix for these Critical findings reported for grype \[Issue [#​3484](https://github.com/anchore/grype/issues/3484)] ##### Additional Changes - Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs \[Issue [#​3493](https://github.com/anchore/grype/issues/3493)] - Security: bump golang.org/x/net to v0.55.0 to resolve CVEs \[Issue [#​3494](https://github.com/anchore/grype/issues/3494)] ##### Dependencies 35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated. **🟢 Remediated (5)** - [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2 - [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2 - [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2 - [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2 - [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2 <details> <summary>Updated (31 packages)</summary> - github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1` - github.com/anchore/bubbly `v0.2.0` → `v0.2.1` - github.com/anchore/clio `v0.1.0` → `v0.1.1` - github.com/anchore/fangs `v0.1.0` → `v0.1.1` - github.com/anchore/go-collections `v0.1.0` → `v0.1.1` - github.com/anchore/go-homedir `v0.1.0` → `v0.1.1` - github.com/anchore/go-logger `v0.1.0` → `v0.1.1` - github.com/anchore/go-lzo `v0.1.0` → `v0.1.1` - github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1` - github.com/anchore/go-make `v0.5.0` → `v0.8.0` - github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2` - github.com/anchore/go-sync `v0.1.0` → `v0.1.1` - github.com/anchore/stereoscope `v0.2.1` → `v0.2.2` - github.com/anchore/syft `v1.45.1` → `v1.46.0` - github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3` - github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0` - github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0` - github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))** - github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible` - github.com/google/go-containerregistry `v0.21.6` → `v0.21.7` - github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21` - github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4` - github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1` - golang.org/x/crypto `v0.52.0` → `v0.53.0` - golang.org/x/mod `v0.36.0` → `v0.37.0` - golang.org/x/net `v0.55.0` → `v0.56.0` - golang.org/x/sync `v0.20.0` → `v0.21.0` - golang.org/x/sys `v0.45.0` → `v0.46.0` - golang.org/x/term `v0.43.0` → `v0.44.0` - golang.org/x/text `v0.37.0` → `v0.38.0` - golang.org/x/tools `v0.45.0` → `v0.46.0` </details> <details> <summary>Added (3 packages)</summary> - github.com/piprate/json-gold `v0.7.0` - github.com/pquerna/cachecontrol `v0.0.0-1555304` - github.com/tailscale/hujson `v0.0.0-ecc657c` </details> <details> <summary>Removed (1 package)</summary> - github.com/google/osv-scanner `v1.9.2` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.114.0...v0.115.0)** ### [`v0.114.0`](https://github.com/anchore/grype/releases/tag/v0.114.0) ##### Added Features - Add ability to scan zarf packages \[[#​3329](https://github.com/anchore/grype/issues/3329) [#​3366](https://github.com/anchore/grype/pull/3366) [@​brandtkeller](https://github.com/brandtkeller)] ##### Additional Changes - respect withdrawn status of Go Vuln DB OSV records \[[#​3495](https://github.com/anchore/grype/pull/3495) [@​willmurphyscode](https://github.com/willmurphyscode)] - Govulndb OSV transformer \[[#​3485](https://github.com/anchore/grype/pull/3485) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.113.0...v0.114.0)** ### [`v0.113.0`](https://github.com/anchore/grype/releases/tag/v0.113.0) ##### Added Features - Include Ubuntu 26.04 "resolute" in distro codenames \[[#​3397](https://github.com/anchore/grype/pull/3397) [@​anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] - source RPM filtering on Hummingbird \[[#​3410](https://github.com/anchore/grype/pull/3410) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - use relatedVulnerabilities description as fallback in SARIF output \[[#​3271](https://github.com/anchore/grype/pull/3271) [@​axidex](https://github.com/axidex)] - improve platform CPE determination logic \[[#​3470](https://github.com/anchore/grype/pull/3470) [@​westonsteimel](https://github.com/westonsteimel)] - normalize uppercase V in semantic version comparison \[[#​3461](https://github.com/anchore/grype/pull/3461) [@​immanuwell](https://github.com/immanuwell)] - purl handling in cgr maven libs \[[#​3420](https://github.com/anchore/grype/pull/3420) [@​willmurphyscode](https://github.com/willmurphyscode)] - Treat uppercase V prefixes the same as lowercase v prefixes in fuzzy version comparison \[[#​3037](https://github.com/anchore/grype/issues/3037) [#​3089](https://github.com/anchore/grype/pull/3089) [@​wasup-yash](https://github.com/wasup-yash)] - Add Runtime Warnings When TLS Verification Is Disabled or HTTP Is Enabled \[[#​3101](https://github.com/anchore/grype/issues/3101) [#​3396](https://github.com/anchore/grype/pull/3396) [@​Dashtid](https://github.com/Dashtid)] - Add support for the aarch64 architecture when parsing the version of Ruby gems in lockfiles \[[#​3442](https://github.com/anchore/grype/issues/3442) [#​3475](https://github.com/anchore/grype/pull/3475) [@​msnandhis](https://github.com/msnandhis)] - zsh completion fails \[[#​2933](https://github.com/anchore/grype/issues/2933) [#​3433](https://github.com/anchore/grype/pull/3433) [@​brandtkeller](https://github.com/brandtkeller)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.112.0...v0.113.0)** ### [`v0.112.0`](https://github.com/anchore/grype/releases/tag/v0.112.0) ##### Added Features - Expand ignore rules to owned sub packages of distro packages \[[#​3368](https://github.com/anchore/grype/issues/3368) [#​3326](https://github.com/anchore/grype/pull/3326) [@​kzantow](https://github.com/kzantow)] ##### Additional Changes - update anchore dependencies \[[#​3391](https://github.com/anchore/grype/pull/3391) [@​anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.1...v0.112.0)** ### [`v0.111.1`](https://github.com/anchore/grype/releases/tag/v0.111.1) ##### Bug Fixes - apply overlap by ownership removal to dynamically created relationships \[[#​3363](https://github.com/anchore/grype/pull/3363) [@​kzantow](https://github.com/kzantow)] - compare mismatched package / db versions \[[#​3372](https://github.com/anchore/grype/pull/3372) [@​kzantow](https://github.com/kzantow)] - Grype doesn't recognize debian component when `"group" : "debian"` is specified \[[#​2967](https://github.com/anchore/grype/issues/2967)] - HelpURI missing information in SARIF output \[[#​2874](https://github.com/anchore/grype/issues/2874) [#​3351](https://github.com/anchore/grype/pull/3351) [@​will-bates11](https://github.com/will-bates11)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.0...v0.111.1)** ### [`v0.108.0`](https://github.com/anchore/grype/releases/tag/v0.108.0) ##### Added Features - enable disabling EOL warnings \[[#​3204](https://github.com/anchore/grype/pull/3204) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - fix fallback on major only distro \[[#​3213](https://github.com/anchore/grype/pull/3213) [@​willmurphyscode](https://github.com/willmurphyscode)] - VEX Documents still not working with syft sbom \[[#​3167](https://github.com/anchore/grype/issues/3167)] - VEX: minimal OpenVEX Example not working \[[#​3212](https://github.com/anchore/grype/issues/3212)] ##### Additional Changes - support more accurate scanning for postmarketos \[[#​3182](https://github.com/anchore/grype/pull/3182) [@​westonsteimel](https://github.com/westonsteimel)] - charmbracelet/bubbletea erases grype ui status line \[[#​3214](https://github.com/anchore/grype/pull/3214) [@​spiffcs](https://github.com/spiffcs)] - bump labels and add several test images \[[#​3215](https://github.com/anchore/grype/pull/3215) [@​westonsteimel](https://github.com/westonsteimel)] - improve VEX product and subcomponent matching \[[#​3168](https://github.com/anchore/grype/pull/3168) [@​dariozachow](https://github.com/dariozachow)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.107.1...v0.108.0)** ### [`v0.105.0`](https://github.com/anchore/grype/releases/tag/v0.105.0) ##### Added Features - Add archlinux matcher to grype \[[#​3154](https://github.com/anchore/grype/pull/3154) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.4...v0.105.0)** ### [`v0.104.4`](https://github.com/anchore/grype/releases/tag/v0.104.4) ##### Bug Fixes - preserve local version segment in constraints for PEP 440 comparison \[[#​3146](https://github.com/anchore/grype/pull/3146) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Additional Changes - correct help text for return code for fail-on severity option \[[#​3138](https://github.com/anchore/grype/pull/3138) [@​u-ways](https://github.com/u-ways)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.3...v0.104.4)** ### [`v0.104.3`](https://github.com/anchore/grype/releases/tag/v0.104.3) ##### Bug Fixes - Use specifier matching rules when comparing python versions \[[#​3121](https://github.com/anchore/grype/pull/3121) [@​wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.2...v0.104.3)** ### [`v0.104.2`](https://github.com/anchore/grype/releases/tag/v0.104.2) ##### Bug Fixes - Since version 0.104.0 shaded jars are not reported \[[#​3098](https://github.com/anchore/grype/issues/3098)] - db search fails with misleading message (out of memory) when no db is present \[[#​3049](https://github.com/anchore/grype/issues/3049) [#​3077](https://github.com/anchore/grype/pull/3077) [@​JvD-Ericsson](https://github.com/JvD-Ericsson)] ##### Additional Changes - replace os.Chdir with t.Chdir in test code \[[#​3067](https://github.com/anchore/grype/pull/3067) [@​joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.1...v0.104.2)** ### [`v0.104.1`](https://github.com/anchore/grype/releases/tag/v0.104.1) ##### Bug Fixes - Redact during file output \[[#​3068](https://github.com/anchore/grype/pull/3068) [@​kzantow](https://github.com/kzantow)] - Unaffected match table does not filter results if CPE matching is enabled \[[#​3056](https://github.com/anchore/grype/issues/3056) [#​3066](https://github.com/anchore/grype/pull/3066) [@​kzantow](https://github.com/kzantow)] ##### Additional Changes - Migrate grype to use `mholt/archives` instead of anchore fork \[[#​3036](https://github.com/anchore/grype/pull/3036) [@​joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.0...v0.104.1)** ### [`v0.104.0`](https://github.com/anchore/grype/releases/tag/v0.104.0) ##### Added Features - Add `--from` flag \[[#​3035](https://github.com/anchore/grype/pull/3035) [@​wagoodman](https://github.com/wagoodman)] - Let a suppression expire to prevent that one will forget to resolve a vulnerability \[[#​3031](https://github.com/anchore/grype/issues/3031)] ##### Bug Fixes - Unnormalized fix version triggers false-positive in mssql-jdbc \[[#​3042](https://github.com/anchore/grype/issues/3042) [#​3034](https://github.com/anchore/grype/pull/3034) [@​jamestexas](https://github.com/jamestexas)] ##### Additional Changes - junit template use CDATA block to prevent XML parse errors \[[#​3019](https://github.com/anchore/grype/pull/3019) [@​nvtkaszpir](https://github.com/nvtkaszpir)] - Keep nested loggers labeled \[[#​3040](https://github.com/anchore/grype/pull/3040) [@​wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.103.0...v0.104.0)** ### [`v0.103.0`](https://github.com/anchore/grype/releases/tag/v0.103.0) ##### Added Features - Allow hyphen in version string \[[#​3021](https://github.com/anchore/grype/pull/3021) [@​willmurphyscode](https://github.com/willmurphyscode)] - Respect rpmmod PURL qualifier \[[#​3020](https://github.com/anchore/grype/pull/3020) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.102.0...v0.103.0)** ### [`v0.102.0`](https://github.com/anchore/grype/releases/tag/v0.102.0) ##### Added Features - Use Alma Linux specific advisories for Alma Linux scans \[[#​2745](https://github.com/anchore/grype/issues/2745) [#​2939](https://github.com/anchore/grype/pull/2939) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - Bitnami packages with CPEs are not matched against CPE-based vulnerabilities \[[#​2997](https://github.com/anchore/grype/issues/2997)] ##### Additional Changes - add markdown template \[[#​2987](https://github.com/anchore/grype/pull/2987) [@​sebdanielsson](https://github.com/sebdanielsson)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.1...v0.102.0)** ### [`v0.101.1`](https://github.com/anchore/grype/releases/tag/v0.101.1) ##### Bug Fixes - Panic error scanning images with v0.101.0 on some java dependencies \[[#​3002](https://github.com/anchore/grype/issues/3002)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.0...v0.101.1)** ### [`v0.101.0`](https://github.com/anchore/grype/releases/tag/v0.101.0) ##### Added Features - Add cyclonedx to RpmMetadata \[[#​2935](https://github.com/anchore/grype/pull/2935) [@​sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)] - `grype db search` can filter by fixed state \[[#​2968](https://github.com/anchore/grype/pull/2968) [@​willmurphyscode](https://github.com/willmurphyscode)] - Support using VEX documents with directory scans and SBOMs \[[#​2471](https://github.com/anchore/grype/issues/2471) [#​2811](https://github.com/anchore/grype/pull/2811) [@​alegrey91](https://github.com/alegrey91)] ##### Bug Fixes - Issue installing Grype using documented curl command \[[#​2985](https://github.com/anchore/grype/issues/2985)] - Advisory ID blank in JSON output \[[#​2965](https://github.com/anchore/grype/issues/2965)] ##### Additional Changes - update flags with v3 to not use default config \[[#​3000](https://github.com/anchore/grype/pull/3000) [@​spiffcs](https://github.com/spiffcs)] - fix Cosign documentation URL in installer \[[#​2995](https://github.com/anchore/grype/pull/2995) [@​lime](https://github.com/lime)] - set advisory id again \[[#​2979](https://github.com/anchore/grype/pull/2979) [@​willmurphyscode](https://github.com/willmurphyscode)] - add db schema validation \[[#​2962](https://github.com/anchore/grype/pull/2962) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.100.0...v0.101.0)** ### [`v0.100.0`](https://github.com/anchore/grype/releases/tag/v0.100.0) ##### Added Features - Add unaffected package and CPE stores \[[#​2888](https://github.com/anchore/grype/pull/2888) [@​wagoodman](https://github.com/wagoodman)] - use unaffected match table to remove appropriate vulns \[[#​2886](https://github.com/anchore/grype/pull/2886) [@​CrosleyZack](https://github.com/CrosleyZack)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.99.1...v0.100.0)** </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/34 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net> Co-committed-by: gitea_admin <admin@forteapps.net>
Kubernetes Cluster - GitOps Configuration
Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)
📚 Complete Documentation
New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:
🎯 START HERE: Documentation Index
| Document | Description | Audience |
|---|---|---|
| GitOps Architecture | System architecture, repository structure, GitOps workflows, security model | Everyone (start here) |
| Developer Guide | Local setup, deploying apps, managing secrets, troubleshooting | Developers |
| Operations Runbook | Cluster bootstrap, day-to-day operations, incident response, maintenance | Platform Engineers, SREs |
| Technical Reference | Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs | Everyone (reference) |
🚀 Quick Start
For New Developers
# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git
# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md
# 3. Deploy your first app (see Developer Guide)
For Operators
# 1. Bootstrap new cluster
./bootstrap.sh
# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces
# 3. Read Operations Runbook for day-to-day tasks
📋 Overview
This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.
What's Inside
- Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
- Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
- Policies: Kyverno security policies for secret management, namespace controls, pod verification
- Monitoring: Full observability stack with metrics, logs, traces, and alerting
- Secrets: Sealed Secrets for secure Git storage
Key Features
✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration
🗂️ Repository Structure
.
├── bootstrap.sh # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/ # Infrastructure provisioning (OpenTofu)
│ ├── platforms/ # Per-platform IaC (one dir per cloud)
│ │ ├── aks/ # Azure AKS (modules/ + dev/ + prod/ + workload/)
│ │ ├── eks/ # AWS EKS
│ │ ├── gke/ # GCP GKE
│ │ └── upc/ # UpCloud
│ ├── configs/ # Platform credentials (git-ignored)
│ │ └── *.env.example # Template for each platform
│ └── scripts/ # Cluster lifecycle scripts
│ ├── setup-cluster.sh # Create cluster: ./setup-cluster.sh aks-dev
│ ├── teardown-cluster.sh
│ └── get-kubeconfig.sh
│
├── clusters/ # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/ # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│ ├── base/ # Base ArgoCD Application manifests (one dir per component)
│ │ ├── kustomization.yaml # Aggregates all component subdirectories
│ │ ├── traefik-application/
│ │ │ ├── kustomization.yaml
│ │ │ └── traefik-application.yaml
│ │ ├── keycloak/
│ │ │ ├── kustomization.yaml
│ │ │ └── keycloak.yaml
│ │ ├── grafana/
│ │ ├── prometheus/
│ │ ├── ... # Each component in its own subdirectory
│ │ └── secrets/
│ ├── overlays/ # Per-cluster overrides (Kustomize)
│ │ ├── upc-dev/ # UpCloud Dev — includes all base components
│ │ ├── upc-prod/ # UpCloud Prod — all components + patches
│ │ ├── aks-dev/ # Azure AKS Dev — selective components only
│ │ ├── aks-prod/ # Azure AKS Prod
│ │ ├── eks-dev/ # AWS EKS Dev
│ │ ├── eks-prod/ # AWS EKS Prod
│ │ ├── gke-dev/ # GCP GKE Dev
│ │ └── gke-prod/ # GCP GKE Prod
│ ├── dashboards/ # Grafana dashboard ConfigMaps
│ └── values/ # Helm value overrides
│ ├── base/ # Shared cloud-agnostic values
│ ├── upc-dev/ # UpCloud Dev (storage, LB, pricing)
│ ├── upc-prod/ # UpCloud Prod
│ ├── eks-dev/ # AWS EKS Dev
│ ├── eks-prod/ # AWS EKS Prod
│ ├── aks-dev/ # Azure AKS Dev
│ ├── aks-prod/ # Azure AKS Prod
│ ├── gke-dev/ # GCP GKE Dev
│ └── gke-prod/ # GCP GKE Prod
│
├── apps/ # Business Applications (Kustomize, same pattern as infra)
│ ├── base/ # One subdirectory per app
│ │ ├── kustomization.yaml
│ │ ├── musicman/
│ │ ├── mcp10x/
│ │ ├── dot-ai-stack/
│ │ ├── ts-mcp/
│ │ └── argo-mcp/
│ └── overlays/ # Per-cluster: cherry-pick or include all
│ ├── upc-dev/ # All apps
│ ├── upc-prod/ # All apps + patches
│ └── aks-dev/ # Selective apps only
│
├── cluster-resources/ # Cluster-wide Kubernetes resources
│ ├── letsencrypt-issuer.yaml
│ ├── kyverno-config.yaml
│ ├── *-sealed.yaml # Sealed secrets
│ └── policies/ # Kyverno policies
│ ├── secret-cloner.yaml
│ ├── default-ns-blocker.yaml
│ ├── bare-pod-cleaner.yaml
│ └── auth-sidecar-injector.yaml
│
├── secrets/ # Application secrets (sealed)
│ └── *-credentials-sealed.yaml
│
├── private/ # Local-only files (Git-ignored)
│ └── *.yaml # Unsealed secrets (never committed)
│
└── docs/ # 📚 Comprehensive documentation
├── README.md # Documentation index
├── GITOPS-ARCHITECTURE.md # Architecture guide
├── DEVELOPER-GUIDE.md # Developer onboarding
├── OPERATIONS-RUNBOOK.md # Operations procedures
└── REFERENCE.md # Technical reference
See GitOps Architecture - Repository Structure for detailed explanation.
🏗️ Architecture
Three-Repository Pattern
| Repository | Purpose | Who Edits | How Often |
|---|---|---|---|
| launchpad (this repo) | ArgoCD Applications, cluster resources | Platform / DevOps engineers | ✅ Often |
| forte-helm | Generic Helm chart templates | Platform engineers | ❌ Rarely |
| helm-prod-values | App-specific configuration & versions | Developers / CI pipelines | ✅ Sometimes |
GitOps Workflow
Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster
Learn more: GitOps Architecture - GitOps Workflow
🔧 Common Tasks
Deploy a New Application
See detailed guide: Developer Guide - Deploying Your First Application
Quick version:
- Create
apps/myapp.yaml(ArgoCD Application manifest) - Create
helm-prod-values/myapp/values.yaml(configuration) - Create sealed secrets if needed
- Commit and push - ArgoCD auto-syncs!
Update an Existing Application
See detailed guide: Developer Guide - Updating an Existing Application
Quick version:
- Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
- Update config: Edit
helm-prod-values/myapp/values.yaml→ commit → push
Manage Secrets
See detailed guide: Developer Guide - Working with Secrets
# Create plain secret
kubectl create secret generic myapp-creds \
--from-literal=KEY=value \
--dry-run=client -o yaml > private/myapp-creds.yaml
# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
< private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml
# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push
Enable Authentication
See detailed guide: Developer Guide - Enabling Authentication
Quick version:
# In helm-prod-values/myapp/values.yaml
# Token-based auth (simple)
auth:
enabled: true
type: token
tokens:
- your-secret-token-here
# OIDC auth (SSO)
auth:
enabled: true
type: oidc
oidc:
authority: https://auth.example.com/realms/master
clientId: myapp
Then create OIDC secret (if using OIDC):
kubectl create secret generic auth-oidc \
--from-literal=client-secret=your-oidc-secret \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=myapp | \
kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
kubectl apply -f -
Bootstrap Cluster
See detailed guide: Operations Runbook - Cluster Bootstrap
# Initialize new cluster
./bootstrap.sh
# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces
🛠️ Quick Reference
Monitor Applications
# List all ArgoCD applications
kubectl get applications -n argocd
# Watch sync status
kubectl get applications -n argocd -w
# Check specific application
kubectl describe application myapp -n argocd
# View application logs
kubectl logs -n myapp <pod-name>
Access UIs
# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)
# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000
# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090
Troubleshooting
# Check pod status
kubectl get pods -n myapp
# View pod logs
kubectl logs -n myapp <pod-name>
# Check pod events
kubectl describe pod -n myapp <pod-name>
# Check ArgoCD sync errors
kubectl describe application myapp -n argocd
# Force sync
kubectl patch application myapp -n argocd \
--type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'
Full troubleshooting guide: Developer Guide - Troubleshooting
🔐 Security
Secret Management
- ✅ Sealed Secrets for Git storage
- ✅ Kyverno auto-clones secrets to namespaces
- ❌ Never commit plain secrets
Network Security
- ✅ All traffic TLS-encrypted (Let's Encrypt)
- ✅ HTTP → HTTPS redirect
- ✅ Traefik IngressRoute per application
Policy Enforcement
- ✅ Kyverno policies for security
- ✅ Default namespace blocked
- ✅ Bare pods not allowed
- ✅ Optional authentication sidecar injection
Learn more: GitOps Architecture - Security Model
📊 Infrastructure Components
| Component | Purpose | Namespace | Replicas |
|---|---|---|---|
| ArgoCD | GitOps controller | argocd |
1 |
| Traefik | Ingress controller | traefik |
2 |
| Cert-Manager | TLS certificates | cert-manager |
1 |
| Kyverno | Policy engine | kyverno |
1 |
| Sealed Secrets | Secret encryption | kube-system |
1 |
| Prometheus | Metrics | monitoring |
1 |
| Grafana | Dashboards | monitoring |
1 |
| Loki | Logs | monitoring |
1 |
| Tempo | Distributed tracing | monitoring |
1 |
| Fluent-Bit | Log shipping | monitoring |
DaemonSet |
| OpenCost | Cost monitoring | monitoring |
1 |
| Renovate | Dependency updates | renovate |
CronJob |
Full specs: Technical Reference - Infrastructure Components
🌐 Domains & Networking
- Local development:
*.127.0.0.1.nip.io - Production:
*.forteapps.net - DNS: Manual configuration (contact platform team)
- TLS: Automatic via Let's Encrypt
📖 Key Concepts
App-of-Apps Pattern
_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.
Multi-Source Pattern
Applications reference both:
- Helm charts from
forte-helm(templates) - Values from
helm-prod-values(configuration)
This separates reusable templates from environment-specific config.
Sync Waves
Applications deploy in order using argocd.argoproj.io/sync-wave:
- Wave
-1: Namespaces - Wave
0: Kyverno (policies) - Wave
1: Infrastructure - Wave
2+: Applications
Auto-Sync & Self-Heal
- Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
- Self-Heal: Manual cluster changes are reverted to match Git
- Prune: Deleted resources in Git are removed from cluster
Learn more: GitOps Architecture - GitOps Workflow
⚙️ Configuration
ArgoCD Settings
- Reconciliation: Every 60 seconds
- Sync timeout: 5 minutes per application
- Retry policy: 5 attempts with exponential backoff
- Authentication: Disabled (internal use only)
Application Defaults
- Auto-sync: Enabled
- Self-heal: Enabled
- Prune: Enabled
- Validation: Server-side validation enabled
- Server-side apply: Enabled
Full configuration: Technical Reference - ArgoCD Configuration
🆘 Getting Help
Documentation
- Start here: Documentation Index
- For development: Developer Guide
- For operations: Operations Runbook
- For reference: Technical Reference
Support
- Slack: #platform-support
- Issues: Contact platform team
- Emergencies: Escalate via Slack
Common Questions
| Question | Answer |
|---|---|
| How do I deploy an app? | Developer Guide - Deploying Your First Application |
| How do I manage secrets? | Developer Guide - Working with Secrets |
| App won't sync? | Developer Guide - Troubleshooting |
| How do I bootstrap a cluster? | Operations Runbook - Cluster Bootstrap |
| Where are the logs? | Operations Runbook - Monitoring & Alerting |
🤝 Contributing
Adding a New Application
- Read Developer Guide - Deploying Your First Application
- Create ArgoCD Application manifest in
apps/ - Create Helm values in
helm-prod-values/ - Create sealed secrets if needed
- Commit and push - ArgoCD handles the rest!
Modifying Infrastructure
- Read Operations Runbook
- Update relevant files in
infra/orcluster-resources/ - Test changes in isolated namespace if possible
- Commit and push
- Monitor sync status in Slack/ArgoCD UI
Updating Documentation
Documentation lives in docs/. To update:
- Edit relevant markdown file
- Update "Last Updated" date
- Submit PR or push directly
- Notify team of significant changes
📝 Notes
Current Environment
- Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
- Active clusters: UpCloud (upc-dev, upc-prod)
- Environment: Production (internal use only)
- Auth: Disabled for ArgoCD (internal access)
- Backup: Gitea daily backup to S3-compatible storage
Known Limitations
- Secret rotation not automated
- DNS management is manual
Future improvements: See Operations Runbook - Disaster Recovery
📚 Additional Resources
External Documentation
- ArgoCD Documentation
- Kyverno Documentation
- Traefik Documentation
- Cert-Manager Documentation
- Grafana Tempo Documentation
- Sealed Secrets
Related Repositories
- forte-helm - Helm chart templates
- helm-prod-values - Application values
📄 License
Internal use only. Not for public distribution.
👥 Maintainers
Platform Team
- Contact: #platform-support on Slack
- Issues: Create issue in repository or contact team directly
Last Updated: 2026-04-22 Documentation Version: 1.0.0
🚀 Ready to get started? Check out the Documentation Index!