52068dc533
/ test (push) Failing after 14m26s
chore(deps): update dependency grype to v0.118.0 (#34)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [grype](https://github.com/anchore/grype) | minor | `0.92.2` → `0.118.0` |

---

### Release Notes

<details>
<summary>anchore/grype (grype)</summary>

### [`v0.118.0`](https://github.com/anchore/grype/releases/tag/v0.118.0)

##### Added Features

- apk matcher does alias aware aggregation \[PR [#&#8203;3634](https://github.com/anchore/grype/pull/3634) [@&#8203;crosleyzack](https://github.com/crosleyzack)]

##### Bug Fixes

- prevent panic on portage versions without digits \[PR [#&#8203;3655](https://github.com/anchore/grype/pull/3655) [@&#8203;ashvinctrl](https://github.com/ashvinctrl)]
- grype vex does not match oci purl with repository\_url \[Issue [#&#8203;3657](https://github.com/anchore/grype/issues/3657)] \[PR [#&#8203;3659](https://github.com/anchore/grype/pull/3659) [@&#8203;spiffcs](https://github.com/spiffcs)]
- Old JVM version comparisons sometimes incorrect \[Issue [#&#8203;2701](https://github.com/anchore/grype/issues/2701)] \[PR [#&#8203;3583](https://github.com/anchore/grype/pull/3583) [@&#8203;Eljees](https://github.com/Eljees)]
- CVSSv4 calculation can produce incorrect vulnerability severity \[Issue [#&#8203;3656](https://github.com/anchore/grype/issues/3656)]
- Grype 0.90.0 DB update failed \[Issue [#&#8203;3629](https://github.com/anchore/grype/issues/3629)]

##### Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

**🟢 Remediated (3)**

- [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835) (Medium) — go.opentelemetry.io/otel
- [GO-2026-6179](https://go.dev/issue/80744) (High) — golang.org/x/mod
- [GO-2026-6180](https://go.dev/issue/80745) (High) — golang.org/x/mod

<details>
<summary>Updated (70 packages)</summary>

- cel.dev/expr `v0.25.1` → `v0.25.2`
- cloud.google.com/go/auth `v0.18.2` → `v0.22.0`
- cloud.google.com/go/iam `v1.5.3` → `v1.11.0`
- cloud.google.com/go/logging `v1.13.1` → `v1.18.0`
- cloud.google.com/go/longrunning `v0.8.0` → `v1.2.0`
- cloud.google.com/go/monitoring `v1.24.3` → `v1.29.0`
- cloud.google.com/go/storage `v1.61.3` → `v1.64.0`
- cloud.google.com/go/trace `v1.11.7` → `v1.16.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.32.0` → `v1.33.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric `v0.55.0` → `v0.57.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock `v0.55.0` → `v0.57.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping `v0.55.0` → `v0.57.0`
- github.com/anchore/stereoscope `v0.3.0` → `v0.3.1`
- github.com/anchore/syft `v1.51.0` → `v1.51.1`
- github.com/aws/aws-sdk-go-v2 `v1.41.5` → `v1.43.4`
- github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream `v1.7.8` → `v1.7.16`
- github.com/aws/aws-sdk-go-v2/config `v1.32.12` → `v1.32.35`
- github.com/aws/aws-sdk-go-v2/credentials `v1.19.12` → `v1.19.34`
- github.com/aws/aws-sdk-go-v2/feature/ec2/imds `v1.18.20` → `v1.18.35`
- github.com/aws/aws-sdk-go-v2/internal/configsources `v1.4.21` → `v1.4.35`
- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 `v2.7.21` → `v2.7.35`
- github.com/aws/aws-sdk-go-v2/internal/v4a `v1.4.22` → `v1.4.36`
- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding `v1.13.7` → `v1.13.15`
- github.com/aws/aws-sdk-go-v2/service/internal/checksum `v1.9.13` → `v1.9.28`
- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url `v1.13.21` → `v1.13.35`
- github.com/aws/aws-sdk-go-v2/service/internal/s3shared `v1.19.21` → `v1.19.36`
- github.com/aws/aws-sdk-go-v2/service/s3 `v1.97.3` → `v1.106.5`
- github.com/aws/aws-sdk-go-v2/service/signin `v1.0.8` → `v1.5.4`
- github.com/aws/aws-sdk-go-v2/service/sso `v1.30.13` → `v1.33.4`
- github.com/aws/aws-sdk-go-v2/service/ssooidc `v1.35.17` → `v1.38.4`
- github.com/aws/aws-sdk-go-v2/service/sts `v1.41.9` → `v1.45.4`
- github.com/aws/smithy-go `v1.24.2` → `v1.27.6`
- github.com/containerd/containerd/v2 `v2.3.3` → `v2.3.4`
- github.com/containerd/platforms `v1.0.0-rc.4` → `v1.0.0-rc.5`
- github.com/docker/cli `v29.6.1+incompatible` → `v29.7.2+incompatible`
- github.com/docker/go-connections `v0.7.0` → `v0.8.1`
- github.com/fatih/color `v1.18.0` → `v1.19.0`
- github.com/google/go-containerregistry `v0.21.7` → `v0.21.9`
- github.com/google/pprof `v0.0.0-6e76a2b` → `v0.0.0-ef3492d`
- github.com/googleapis/enterprise-certificate-proxy `v0.3.14` → `v0.3.19`
- github.com/googleapis/gax-go/v2 `v2.17.0` → `v2.23.0`
- github.com/hashicorp/aws-sdk-go-base/v2 `v2.0.0-beta.72` → `v2.0.0-beta.74`
- github.com/hashicorp/go-getter `v1.8.6` → `v1.8.8`
- github.com/hashicorp/go-version `v1.8.0` → `v1.9.0`
- github.com/klauspost/compress `v1.19.1` → `v1.19.2`
- github.com/mattn/go-isatty `v0.0.20` → `v0.0.24`
- github.com/moby/moby/client `v0.5.0` → `v0.5.1`
- github.com/spiffe/go-spiffe/v2 `v2.6.0` → `v2.7.0`
- github.com/stretchr/objx `v0.5.2` → `v0.5.3`
- github.com/stretchr/testify `v1.11.1` → `v1.12.1`
- go.opentelemetry.io/contrib/detectors/gcp `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel `v1.43.0` → `v1.44.0` **(🟢 remediated [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835))**
- go.opentelemetry.io/otel/exporters/stdout/stdoutmetric `v1.40.0` → `v1.44.0`
- go.opentelemetry.io/otel/metric `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/sdk `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/sdk/metric `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/trace `v1.43.0` → `v1.44.0`
- golang.org/x/crypto `v0.54.0` → `v0.55.0`
- golang.org/x/mod `v0.38.0` → `v0.40.0` **(🟢 remediated [GO-2026-6179](https://go.dev/issue/80744), [GO-2026-6180](https://go.dev/issue/80745))**
- golang.org/x/net `v0.57.0` → `v0.58.0`
- golang.org/x/text `v0.40.0` → `v0.41.0`
- golang.org/x/tools `v0.48.0` → `v0.49.0`
- google.golang.org/api `v0.271.0` → `v0.292.0`
- google.golang.org/genproto `v0.0.0-8636f87` → `v0.0.0-aa98bba`
- google.golang.org/genproto/googleapis/api `v0.0.0-afd174a` → `v0.0.0-925bb5d`
- google.golang.org/genproto/googleapis/rpc `v0.0.0-afd174a` → `v0.0.0-6ac0973`
- google.golang.org/grpc `v1.82.1` → `v1.83.0`
- modernc.org/cc/v4 `v4.29.0` → `v4.29.1`
- modernc.org/libc `v1.74.1` → `v1.74.4`
- modernc.org/sqlite `v1.55.0` → `v1.56.0`

</details>

<details>
<summary>Added (1 package)</summary>

- go.opentelemetry.io/otel/metric/x `v0.66.0`

</details>

<details>
<summary>Removed (1 package)</summary>

- github.com/aws/aws-sdk-go-v2/internal/ini `v1.8.6`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.117.0...v0.118.0)**

### [`v0.117.0`](https://github.com/anchore/grype/releases/tag/v0.117.0)

##### Added Features

- Include vulnerable ranges in CycloneDX output format \[Issue [#&#8203;3512](https://github.com/anchore/grype/issues/3512)] \[PR [#&#8203;3519](https://github.com/anchore/grype/pull/3519) [@&#8203;somaz94](https://github.com/somaz94)]

##### Bug Fixes

- honor match.rust.using-cpes configuration \[PR [#&#8203;3611](https://github.com/anchore/grype/pull/3611) [@&#8203;Dashtid](https://github.com/Dashtid)]

##### Dependencies

11 dependency changes (11 updated). 2 vulnerabilities remediated.

**🟢 Remediated (2)**

- [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5
- [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5

<details>
<summary>Updated (11 packages)</summary>

- github.com/anchore/syft `v1.50.0` → `v1.51.0`
- github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4`
- github.com/gabriel-vasile/mimetype `v1.4.13` → `v1.4.15`
- github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1`
- github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))**
- github.com/klauspost/compress `v1.19.0` → `v1.19.1`
- github.com/magiconair/properties `v1.8.10` → `v1.18.11`
- github.com/santhosh-tekuri/jsonschema/v6 `v6.0.2` → `v6.0.3`
- github.com/ulikunitz/xz `v0.5.15` → `v0.5.16`
- go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5`
- modernc.org/sqlite `v1.54.0` → `v1.55.0`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.1...v0.117.0)**

### [`v0.116.1`](https://github.com/anchore/grype/releases/tag/v0.116.1)

##### Bug Fixes

- Ensure channel parsing is consistent \[PR [#&#8203;3603](https://github.com/anchore/grype/pull/3603) [@&#8203;wagoodman](https://github.com/wagoodman)]
- Scope Go GHSA twins by shared CVE \[PR [#&#8203;3592](https://github.com/anchore/grype/pull/3592) [@&#8203;wagoodman](https://github.com/wagoodman)]
- do not cache a comparator that failed to build \[PR [#&#8203;3567](https://github.com/anchore/grype/pull/3567) [@&#8203;arpitjain099](https://github.com/arpitjain099)]
- Add fix date to rhel minor records created from rhsa \[PR [#&#8203;3585](https://github.com/anchore/grype/pull/3585) [@&#8203;wagoodman](https://github.com/wagoodman)]
- grype reporting CVE-64091 as critical - redhat says it is not affected \[Issue [#&#8203;3591](https://github.com/anchore/grype/issues/3591)]
- panic: index out of range in distro.parseVersion for VERSION\_ID=v \[Issue [#&#8203;3588](https://github.com/anchore/grype/issues/3588)] \[PR [#&#8203;3589](https://github.com/anchore/grype/pull/3589) [@&#8203;matiasinsaurralde](https://github.com/matiasinsaurralde)]
- False Positive: GO-2026-5932 \[Issue [#&#8203;3573](https://github.com/anchore/grype/issues/3573)]

##### Dependencies

30 dependency changes (30 updated). 1 vulnerability remediated.

**🟢 Remediated (1)**

- [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc

<details>
<summary>Updated (30 packages)</summary>

- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0`
- github.com/anchore/stereoscope `v0.2.2` → `v0.3.0`
- github.com/anchore/syft `v1.48.0` → `v1.50.0`
- github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58`
- github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3`
- github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible`
- github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0`
- github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3`
- github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23`
- github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0`
- github.com/moby/moby/api `v1.54.2` → `v1.55.0`
- github.com/moby/moby/client `v0.4.1` → `v0.5.0`
- github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3`
- go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0`
- golang.org/x/crypto `v0.53.0` → `v0.54.0`
- golang.org/x/mod `v0.37.0` → `v0.38.0`
- golang.org/x/net `v0.56.0` → `v0.57.0`
- golang.org/x/sync `v0.21.0` → `v0.22.0`
- golang.org/x/sys `v0.46.0` → `v0.47.0`
- golang.org/x/term `v0.44.0` → `v0.45.0`
- golang.org/x/text `v0.39.0` → `v0.40.0`
- golang.org/x/tools `v0.47.0` → `v0.48.0`
- google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a`
- google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a`
- google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))**
- modernc.org/cc/v4 `v4.28.4` → `v4.29.0`
- modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6`
- modernc.org/gc/v3 `v3.1.3` → `v3.1.4`
- modernc.org/libc `v1.73.4` → `v1.74.1`
- modernc.org/sqlite `v1.53.0` → `v1.54.0`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.0...v0.116.1)**

### [`v0.115.0`](https://github.com/anchore/grype/releases/tag/v0.115.0)

##### Added Features

- emit golang.org/x/net vulns from govlundb \[PR [#&#8203;3534](https://github.com/anchore/grype/pull/3534) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Merge Go vuln matches with GHSA matches \[Issue [#&#8203;3515](https://github.com/anchore/grype/issues/3515)]

##### Bug Fixes

- only emit records for stdlib \[PR [#&#8203;3527](https://github.com/anchore/grype/pull/3527) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- mark hummingbird distro as rolling \[PR [#&#8203;3521](https://github.com/anchore/grype/pull/3521) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- disable go stdlib CPE matching by default \[PR [#&#8203;3517](https://github.com/anchore/grype/pull/3517) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- merge in custom ranges when applicable \[PR [#&#8203;3514](https://github.com/anchore/grype/pull/3514) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- exclude linux-kbuild deb indirect matches by default \[PR [#&#8203;3506](https://github.com/anchore/grype/pull/3506) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- avoid panic on invalid RHEL version IDs \[PR [#&#8203;3490](https://github.com/anchore/grype/pull/3490) [@&#8203;jspilman](https://github.com/jspilman)]
- Support reading CycloneDX 1.7 SBOMs \[Issue [#&#8203;3373](https://github.com/anchore/grype/issues/3373)]
- Grype cannot read mariadb version correctly \[Issue [#&#8203;3452](https://github.com/anchore/grype/issues/3452)]
- grype hangs when downloading certain images using registry client \[Issue [#&#8203;3492](https://github.com/anchore/grype/issues/3492)]
- Can we get a fix for these Critical findings reported for grype \[Issue [#&#8203;3484](https://github.com/anchore/grype/issues/3484)]

##### Additional Changes

- Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs \[Issue [#&#8203;3493](https://github.com/anchore/grype/issues/3493)]
- Security: bump golang.org/x/net to v0.55.0 to resolve CVEs \[Issue [#&#8203;3494](https://github.com/anchore/grype/issues/3494)]

##### Dependencies

35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated.

**🟢 Remediated (5)**

- [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2
- [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2
- [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2
- [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2
- [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2

<details>
<summary>Updated (31 packages)</summary>

- github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1`
- github.com/anchore/bubbly `v0.2.0` → `v0.2.1`
- github.com/anchore/clio `v0.1.0` → `v0.1.1`
- github.com/anchore/fangs `v0.1.0` → `v0.1.1`
- github.com/anchore/go-collections `v0.1.0` → `v0.1.1`
- github.com/anchore/go-homedir `v0.1.0` → `v0.1.1`
- github.com/anchore/go-logger `v0.1.0` → `v0.1.1`
- github.com/anchore/go-lzo `v0.1.0` → `v0.1.1`
- github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1`
- github.com/anchore/go-make `v0.5.0` → `v0.8.0`
- github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2`
- github.com/anchore/go-sync `v0.1.0` → `v0.1.1`
- github.com/anchore/stereoscope `v0.2.1` → `v0.2.2`
- github.com/anchore/syft `v1.45.1` → `v1.46.0`
- github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3`
- github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0`
- github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0`
- github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))**
- github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible`
- github.com/google/go-containerregistry `v0.21.6` → `v0.21.7`
- github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21`
- github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4`
- github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1`
- golang.org/x/crypto `v0.52.0` → `v0.53.0`
- golang.org/x/mod `v0.36.0` → `v0.37.0`
- golang.org/x/net `v0.55.0` → `v0.56.0`
- golang.org/x/sync `v0.20.0` → `v0.21.0`
- golang.org/x/sys `v0.45.0` → `v0.46.0`
- golang.org/x/term `v0.43.0` → `v0.44.0`
- golang.org/x/text `v0.37.0` → `v0.38.0`
- golang.org/x/tools `v0.45.0` → `v0.46.0`

</details>

<details>
<summary>Added (3 packages)</summary>

- github.com/piprate/json-gold `v0.7.0`
- github.com/pquerna/cachecontrol `v0.0.0-1555304`
- github.com/tailscale/hujson `v0.0.0-ecc657c`

</details>

<details>
<summary>Removed (1 package)</summary>

- github.com/google/osv-scanner `v1.9.2`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.114.0...v0.115.0)**

### [`v0.114.0`](https://github.com/anchore/grype/releases/tag/v0.114.0)

##### Added Features

- Add ability to scan zarf packages \[[#&#8203;3329](https://github.com/anchore/grype/issues/3329) [#&#8203;3366](https://github.com/anchore/grype/pull/3366) [@&#8203;brandtkeller](https://github.com/brandtkeller)]

##### Additional Changes

- respect withdrawn status of Go Vuln DB OSV records \[[#&#8203;3495](https://github.com/anchore/grype/pull/3495) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Govulndb OSV transformer \[[#&#8203;3485](https://github.com/anchore/grype/pull/3485) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.113.0...v0.114.0)**

### [`v0.113.0`](https://github.com/anchore/grype/releases/tag/v0.113.0)

##### Added Features

- Include Ubuntu 26.04 "resolute" in distro codenames \[[#&#8203;3397](https://github.com/anchore/grype/pull/3397) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)]
- source RPM filtering on Hummingbird \[[#&#8203;3410](https://github.com/anchore/grype/pull/3410) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- use relatedVulnerabilities description as fallback in SARIF output \[[#&#8203;3271](https://github.com/anchore/grype/pull/3271) [@&#8203;axidex](https://github.com/axidex)]
- improve platform CPE determination logic \[[#&#8203;3470](https://github.com/anchore/grype/pull/3470) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- normalize uppercase V in semantic version comparison \[[#&#8203;3461](https://github.com/anchore/grype/pull/3461) [@&#8203;immanuwell](https://github.com/immanuwell)]
- purl handling in cgr maven libs \[[#&#8203;3420](https://github.com/anchore/grype/pull/3420) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Treat uppercase V prefixes the same as lowercase v prefixes in fuzzy version comparison \[[#&#8203;3037](https://github.com/anchore/grype/issues/3037) [#&#8203;3089](https://github.com/anchore/grype/pull/3089) [@&#8203;wasup-yash](https://github.com/wasup-yash)]
- Add Runtime Warnings When TLS Verification Is Disabled or HTTP Is Enabled \[[#&#8203;3101](https://github.com/anchore/grype/issues/3101) [#&#8203;3396](https://github.com/anchore/grype/pull/3396) [@&#8203;Dashtid](https://github.com/Dashtid)]
- Add support for the aarch64 architecture when parsing the version of Ruby gems in lockfiles \[[#&#8203;3442](https://github.com/anchore/grype/issues/3442) [#&#8203;3475](https://github.com/anchore/grype/pull/3475) [@&#8203;msnandhis](https://github.com/msnandhis)]
- zsh completion fails \[[#&#8203;2933](https://github.com/anchore/grype/issues/2933) [#&#8203;3433](https://github.com/anchore/grype/pull/3433) [@&#8203;brandtkeller](https://github.com/brandtkeller)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.112.0...v0.113.0)**

### [`v0.112.0`](https://github.com/anchore/grype/releases/tag/v0.112.0)

##### Added Features

- Expand ignore rules to owned sub packages of distro packages \[[#&#8203;3368](https://github.com/anchore/grype/issues/3368) [#&#8203;3326](https://github.com/anchore/grype/pull/3326) [@&#8203;kzantow](https://github.com/kzantow)]

##### Additional Changes

- update anchore dependencies \[[#&#8203;3391](https://github.com/anchore/grype/pull/3391) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.1...v0.112.0)**

### [`v0.111.1`](https://github.com/anchore/grype/releases/tag/v0.111.1)

##### Bug Fixes

- apply overlap by ownership removal to dynamically created relationships \[[#&#8203;3363](https://github.com/anchore/grype/pull/3363) [@&#8203;kzantow](https://github.com/kzantow)]
- compare mismatched package / db versions \[[#&#8203;3372](https://github.com/anchore/grype/pull/3372) [@&#8203;kzantow](https://github.com/kzantow)]
- Grype doesn't recognize debian component when `"group" : "debian"` is specified \[[#&#8203;2967](https://github.com/anchore/grype/issues/2967)]
- HelpURI missing information in SARIF output \[[#&#8203;2874](https://github.com/anchore/grype/issues/2874) [#&#8203;3351](https://github.com/anchore/grype/pull/3351) [@&#8203;will-bates11](https://github.com/will-bates11)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.0...v0.111.1)**

### [`v0.108.0`](https://github.com/anchore/grype/releases/tag/v0.108.0)

##### Added Features

- enable disabling EOL warnings \[[#&#8203;3204](https://github.com/anchore/grype/pull/3204) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- fix fallback on major only distro \[[#&#8203;3213](https://github.com/anchore/grype/pull/3213) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- VEX Documents still not working with syft sbom \[[#&#8203;3167](https://github.com/anchore/grype/issues/3167)]
- VEX: minimal OpenVEX Example not working \[[#&#8203;3212](https://github.com/anchore/grype/issues/3212)]

##### Additional Changes

- support more accurate scanning for postmarketos \[[#&#8203;3182](https://github.com/anchore/grype/pull/3182) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- charmbracelet/bubbletea erases grype ui status line \[[#&#8203;3214](https://github.com/anchore/grype/pull/3214) [@&#8203;spiffcs](https://github.com/spiffcs)]
- bump labels and add several test images \[[#&#8203;3215](https://github.com/anchore/grype/pull/3215) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- improve VEX product and subcomponent matching \[[#&#8203;3168](https://github.com/anchore/grype/pull/3168) [@&#8203;dariozachow](https://github.com/dariozachow)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.107.1...v0.108.0)**

### [`v0.105.0`](https://github.com/anchore/grype/releases/tag/v0.105.0)

##### Added Features

- Add archlinux matcher to grype \[[#&#8203;3154](https://github.com/anchore/grype/pull/3154) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.4...v0.105.0)**

### [`v0.104.4`](https://github.com/anchore/grype/releases/tag/v0.104.4)

##### Bug Fixes

- preserve local version segment in constraints for PEP 440 comparison \[[#&#8203;3146](https://github.com/anchore/grype/pull/3146) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Additional Changes

- correct help text for return code for fail-on severity option \[[#&#8203;3138](https://github.com/anchore/grype/pull/3138) [@&#8203;u-ways](https://github.com/u-ways)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.3...v0.104.4)**

### [`v0.104.3`](https://github.com/anchore/grype/releases/tag/v0.104.3)

##### Bug Fixes

- Use specifier matching rules when comparing python versions \[[#&#8203;3121](https://github.com/anchore/grype/pull/3121) [@&#8203;wagoodman](https://github.com/wagoodman)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.2...v0.104.3)**

### [`v0.104.2`](https://github.com/anchore/grype/releases/tag/v0.104.2)

##### Bug Fixes

- Since version 0.104.0 shaded jars are not reported \[[#&#8203;3098](https://github.com/anchore/grype/issues/3098)]
- db search fails with misleading message (out of memory) when no db is present \[[#&#8203;3049](https://github.com/anchore/grype/issues/3049) [#&#8203;3077](https://github.com/anchore/grype/pull/3077) [@&#8203;JvD-Ericsson](https://github.com/JvD-Ericsson)]

##### Additional Changes

- replace os.Chdir with t.Chdir in test code \[[#&#8203;3067](https://github.com/anchore/grype/pull/3067) [@&#8203;joonas](https://github.com/joonas)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.1...v0.104.2)**

### [`v0.104.1`](https://github.com/anchore/grype/releases/tag/v0.104.1)

##### Bug Fixes

- Redact during file output \[[#&#8203;3068](https://github.com/anchore/grype/pull/3068) [@&#8203;kzantow](https://github.com/kzantow)]
- Unaffected match table does not filter results if CPE matching is enabled \[[#&#8203;3056](https://github.com/anchore/grype/issues/3056) [#&#8203;3066](https://github.com/anchore/grype/pull/3066) [@&#8203;kzantow](https://github.com/kzantow)]

##### Additional Changes

- Migrate grype to use `mholt/archives` instead of anchore fork \[[#&#8203;3036](https://github.com/anchore/grype/pull/3036) [@&#8203;joonas](https://github.com/joonas)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.0...v0.104.1)**

### [`v0.104.0`](https://github.com/anchore/grype/releases/tag/v0.104.0)

##### Added Features

- Add `--from` flag \[[#&#8203;3035](https://github.com/anchore/grype/pull/3035) [@&#8203;wagoodman](https://github.com/wagoodman)]
- Let a suppression expire to prevent that one will forget to resolve a vulnerability \[[#&#8203;3031](https://github.com/anchore/grype/issues/3031)]

##### Bug Fixes

- Unnormalized fix version triggers false-positive in mssql-jdbc \[[#&#8203;3042](https://github.com/anchore/grype/issues/3042) [#&#8203;3034](https://github.com/anchore/grype/pull/3034) [@&#8203;jamestexas](https://github.com/jamestexas)]

##### Additional Changes

- junit template use CDATA block to prevent XML parse errors \[[#&#8203;3019](https://github.com/anchore/grype/pull/3019) [@&#8203;nvtkaszpir](https://github.com/nvtkaszpir)]
- Keep nested loggers labeled \[[#&#8203;3040](https://github.com/anchore/grype/pull/3040) [@&#8203;wagoodman](https://github.com/wagoodman)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.103.0...v0.104.0)**

### [`v0.103.0`](https://github.com/anchore/grype/releases/tag/v0.103.0)

##### Added Features

- Allow hyphen in version string \[[#&#8203;3021](https://github.com/anchore/grype/pull/3021) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Respect rpmmod PURL qualifier \[[#&#8203;3020](https://github.com/anchore/grype/pull/3020) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.102.0...v0.103.0)**

### [`v0.102.0`](https://github.com/anchore/grype/releases/tag/v0.102.0)

##### Added Features

- Use Alma Linux specific advisories for Alma Linux scans \[[#&#8203;2745](https://github.com/anchore/grype/issues/2745) [#&#8203;2939](https://github.com/anchore/grype/pull/2939) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- Bitnami packages with CPEs are not matched against CPE-based vulnerabilities \[[#&#8203;2997](https://github.com/anchore/grype/issues/2997)]

##### Additional Changes

- add markdown template \[[#&#8203;2987](https://github.com/anchore/grype/pull/2987) [@&#8203;sebdanielsson](https://github.com/sebdanielsson)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.1...v0.102.0)**

### [`v0.101.1`](https://github.com/anchore/grype/releases/tag/v0.101.1)

##### Bug Fixes

- Panic error scanning images with v0.101.0 on some java dependencies \[[#&#8203;3002](https://github.com/anchore/grype/issues/3002)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.0...v0.101.1)**

### [`v0.101.0`](https://github.com/anchore/grype/releases/tag/v0.101.0)

##### Added Features

- Add cyclonedx to RpmMetadata \[[#&#8203;2935](https://github.com/anchore/grype/pull/2935) [@&#8203;sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)]
- `grype db search` can filter by fixed state \[[#&#8203;2968](https://github.com/anchore/grype/pull/2968) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Support using VEX documents with directory scans and SBOMs \[[#&#8203;2471](https://github.com/anchore/grype/issues/2471) [#&#8203;2811](https://github.com/anchore/grype/pull/2811) [@&#8203;alegrey91](https://github.com/alegrey91)]

##### Bug Fixes

- Issue installing Grype using documented curl command \[[#&#8203;2985](https://github.com/anchore/grype/issues/2985)]
- Advisory ID blank in JSON output \[[#&#8203;2965](https://github.com/anchore/grype/issues/2965)]

##### Additional Changes

- update flags with v3 to not use default config \[[#&#8203;3000](https://github.com/anchore/grype/pull/3000) [@&#8203;spiffcs](https://github.com/spiffcs)]
- fix Cosign documentation URL in installer \[[#&#8203;2995](https://github.com/anchore/grype/pull/2995) [@&#8203;lime](https://github.com/lime)]
- set advisory id again \[[#&#8203;2979](https://github.com/anchore/grype/pull/2979) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- add db schema validation \[[#&#8203;2962](https://github.com/anchore/grype/pull/2962) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.100.0...v0.101.0)**

### [`v0.100.0`](https://github.com/anchore/grype/releases/tag/v0.100.0)

##### Added Features

- Add unaffected package and CPE stores \[[#&#8203;2888](https://github.com/anchore/grype/pull/2888) [@&#8203;wagoodman](https://github.com/wagoodman)]
- use unaffected match table to remove appropriate vulns \[[#&#8203;2886](https://github.com/anchore/grype/pull/2886) [@&#8203;CrosleyZack](https://github.com/CrosleyZack)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.99.1...v0.100.0)**

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/34
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
2026-09-27 22:15:50 +00:00
2026-07-02 12:25:11 +02:00
2026-05-31 20:48:25 +02:00
2026-09-23 20:30:09 +02:00
2026-04-27 11:33:24 +02:00
2026-08-01 12:10:50 +02:00
2026-04-24 08:48:53 +00:00
2026-04-28 20:38:59 +02:00
2026-04-18 18:14:00 +00:00
2026-04-25 11:49:17 +02:00
2026-05-29 15:48:28 +00:00
2026-06-29 17:02:50 +02:00
2026-04-28 20:38:59 +02:00
2026-05-29 15:48:28 +00:00
2026-09-27 22:11:47 +00:00

Kubernetes Cluster - GitOps Configuration

Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)

GitOps Kubernetes


📚 Complete Documentation

New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:

🎯 START HERE: Documentation Index

Document Description Audience
GitOps Architecture System architecture, repository structure, GitOps workflows, security model Everyone (start here)
Developer Guide Local setup, deploying apps, managing secrets, troubleshooting Developers
Operations Runbook Cluster bootstrap, day-to-day operations, incident response, maintenance Platform Engineers, SREs
Technical Reference Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs Everyone (reference)

🚀 Quick Start

For New Developers

# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git

# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md

# 3. Deploy your first app (see Developer Guide)

For Operators

# 1. Bootstrap new cluster
./bootstrap.sh

# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces

# 3. Read Operations Runbook for day-to-day tasks

📋 Overview

This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.

What's Inside

  • Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
  • Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
  • Policies: Kyverno security policies for secret management, namespace controls, pod verification
  • Monitoring: Full observability stack with metrics, logs, traces, and alerting
  • Secrets: Sealed Secrets for secure Git storage

Key Features

✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration


🗂️ Repository Structure

.
├── bootstrap.sh                # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/                     # Infrastructure provisioning (OpenTofu)
│   ├── platforms/             # Per-platform IaC (one dir per cloud)
│   │   ├── aks/               # Azure AKS (modules/ + dev/ + prod/ + workload/)
│   │   ├── eks/               # AWS EKS
│   │   ├── gke/               # GCP GKE
│   │   └── upc/               # UpCloud
│   ├── configs/               # Platform credentials (git-ignored)
│   │   └── *.env.example      # Template for each platform
│   └── scripts/               # Cluster lifecycle scripts
│       ├── setup-cluster.sh   # Create cluster: ./setup-cluster.sh aks-dev
│       ├── teardown-cluster.sh
│       └── get-kubeconfig.sh
│
├── clusters/                  # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/                     # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│   ├── base/                  # Base ArgoCD Application manifests (one dir per component)
│   │   ├── kustomization.yaml # Aggregates all component subdirectories
│   │   ├── traefik-application/
│   │   │   ├── kustomization.yaml
│   │   │   └── traefik-application.yaml
│   │   ├── keycloak/
│   │   │   ├── kustomization.yaml
│   │   │   └── keycloak.yaml
│   │   ├── grafana/
│   │   ├── prometheus/
│   │   ├── ...               # Each component in its own subdirectory
│   │   └── secrets/
│   ├── overlays/              # Per-cluster overrides (Kustomize)
│   │   ├── upc-dev/           # UpCloud Dev — includes all base components
│   │   ├── upc-prod/         # UpCloud Prod — all components + patches
│   │   ├── aks-dev/          # Azure AKS Dev — selective components only
│   │   ├── aks-prod/         # Azure AKS Prod
│   │   ├── eks-dev/           # AWS EKS Dev
│   │   ├── eks-prod/         # AWS EKS Prod
│   │   ├── gke-dev/          # GCP GKE Dev
│   │   └── gke-prod/         # GCP GKE Prod
│   ├── dashboards/            # Grafana dashboard ConfigMaps
│   └── values/                # Helm value overrides
│       ├── base/              # Shared cloud-agnostic values
│       ├── upc-dev/           # UpCloud Dev (storage, LB, pricing)
│       ├── upc-prod/         # UpCloud Prod
│       ├── eks-dev/           # AWS EKS Dev
│       ├── eks-prod/         # AWS EKS Prod
│       ├── aks-dev/        # Azure AKS Dev
│       ├── aks-prod/       # Azure AKS Prod
│       ├── gke-dev/          # GCP GKE Dev
│       └── gke-prod/         # GCP GKE Prod
│
├── apps/                      # Business Applications (Kustomize, same pattern as infra)
│   ├── base/                  # One subdirectory per app
│   │   ├── kustomization.yaml
│   │   ├── musicman/
│   │   ├── mcp10x/
│   │   ├── dot-ai-stack/
│   │   ├── ts-mcp/
│   │   └── argo-mcp/
│   └── overlays/              # Per-cluster: cherry-pick or include all
│       ├── upc-dev/           # All apps
│       ├── upc-prod/         # All apps + patches
│       └── aks-dev/          # Selective apps only
│
├── cluster-resources/         # Cluster-wide Kubernetes resources
│   ├── letsencrypt-issuer.yaml
│   ├── kyverno-config.yaml
│   ├── *-sealed.yaml          # Sealed secrets
│   └── policies/              # Kyverno policies
│       ├── secret-cloner.yaml
│       ├── default-ns-blocker.yaml
│       ├── bare-pod-cleaner.yaml
│       └── auth-sidecar-injector.yaml
│
├── secrets/                   # Application secrets (sealed)
│   └── *-credentials-sealed.yaml
│
├── private/                   # Local-only files (Git-ignored)
│   └── *.yaml                 # Unsealed secrets (never committed)
│
└── docs/                      # 📚 Comprehensive documentation
    ├── README.md              # Documentation index
    ├── GITOPS-ARCHITECTURE.md # Architecture guide
    ├── DEVELOPER-GUIDE.md     # Developer onboarding
    ├── OPERATIONS-RUNBOOK.md  # Operations procedures
    └── REFERENCE.md           # Technical reference

See GitOps Architecture - Repository Structure for detailed explanation.


🏗️ Architecture

Three-Repository Pattern

Repository Purpose Who Edits How Often
launchpad (this repo) ArgoCD Applications, cluster resources Platform / DevOps engineers ✅ Often
forte-helm Generic Helm chart templates Platform engineers ❌ Rarely
helm-prod-values App-specific configuration & versions Developers / CI pipelines ✅ Sometimes

GitOps Workflow

Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster

Learn more: GitOps Architecture - GitOps Workflow


🔧 Common Tasks

Deploy a New Application

See detailed guide: Developer Guide - Deploying Your First Application

Quick version:

  1. Create apps/myapp.yaml (ArgoCD Application manifest)
  2. Create helm-prod-values/myapp/values.yaml (configuration)
  3. Create sealed secrets if needed
  4. Commit and push - ArgoCD auto-syncs!

Update an Existing Application

See detailed guide: Developer Guide - Updating an Existing Application

Quick version:

  • Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
  • Update config: Edit helm-prod-values/myapp/values.yaml → commit → push

Manage Secrets

See detailed guide: Developer Guide - Working with Secrets

# Create plain secret
kubectl create secret generic myapp-creds \
  --from-literal=KEY=value \
  --dry-run=client -o yaml > private/myapp-creds.yaml

# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
  < private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml

# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push

Enable Authentication

See detailed guide: Developer Guide - Enabling Authentication

Quick version:

# In helm-prod-values/myapp/values.yaml

# Token-based auth (simple)
auth:
  enabled: true
  type: token
  tokens:
  - your-secret-token-here

# OIDC auth (SSO)
auth:
  enabled: true
  type: oidc
  oidc:
    authority: https://auth.example.com/realms/master
    clientId: myapp

Then create OIDC secret (if using OIDC):

kubectl create secret generic auth-oidc \
  --from-literal=client-secret=your-oidc-secret \
  --from-literal=cookie-secret=$(openssl rand -hex 32) \
  --namespace=myapp | \
  kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
  kubectl apply -f -

Bootstrap Cluster

See detailed guide: Operations Runbook - Cluster Bootstrap

# Initialize new cluster
./bootstrap.sh

# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces

🛠️ Quick Reference

Monitor Applications

# List all ArgoCD applications
kubectl get applications -n argocd

# Watch sync status
kubectl get applications -n argocd -w

# Check specific application
kubectl describe application myapp -n argocd

# View application logs
kubectl logs -n myapp <pod-name>

Access UIs

# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)

# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000

# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090

Troubleshooting

# Check pod status
kubectl get pods -n myapp

# View pod logs
kubectl logs -n myapp <pod-name>

# Check pod events
kubectl describe pod -n myapp <pod-name>

# Check ArgoCD sync errors
kubectl describe application myapp -n argocd

# Force sync
kubectl patch application myapp -n argocd \
  --type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'

Full troubleshooting guide: Developer Guide - Troubleshooting


🔐 Security

Secret Management

  • ✅ Sealed Secrets for Git storage
  • ✅ Kyverno auto-clones secrets to namespaces
  • ❌ Never commit plain secrets

Network Security

  • ✅ All traffic TLS-encrypted (Let's Encrypt)
  • ✅ HTTP → HTTPS redirect
  • ✅ Traefik IngressRoute per application

Policy Enforcement

  • ✅ Kyverno policies for security
  • ✅ Default namespace blocked
  • ✅ Bare pods not allowed
  • ✅ Optional authentication sidecar injection

Learn more: GitOps Architecture - Security Model


📊 Infrastructure Components

Component Purpose Namespace Replicas
ArgoCD GitOps controller argocd 1
Traefik Ingress controller traefik 2
Cert-Manager TLS certificates cert-manager 1
Kyverno Policy engine kyverno 1
Sealed Secrets Secret encryption kube-system 1
Prometheus Metrics monitoring 1
Grafana Dashboards monitoring 1
Loki Logs monitoring 1
Tempo Distributed tracing monitoring 1
Fluent-Bit Log shipping monitoring DaemonSet
OpenCost Cost monitoring monitoring 1
Renovate Dependency updates renovate CronJob

Full specs: Technical Reference - Infrastructure Components


🌐 Domains & Networking

  • Local development: *.127.0.0.1.nip.io
  • Production: *.forteapps.net
  • DNS: Manual configuration (contact platform team)
  • TLS: Automatic via Let's Encrypt

📖 Key Concepts

App-of-Apps Pattern

_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.

Multi-Source Pattern

Applications reference both:

  1. Helm charts from forte-helm (templates)
  2. Values from helm-prod-values (configuration)

This separates reusable templates from environment-specific config.

Sync Waves

Applications deploy in order using argocd.argoproj.io/sync-wave:

  • Wave -1: Namespaces
  • Wave 0: Kyverno (policies)
  • Wave 1: Infrastructure
  • Wave 2+: Applications

Auto-Sync & Self-Heal

  • Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
  • Self-Heal: Manual cluster changes are reverted to match Git
  • Prune: Deleted resources in Git are removed from cluster

Learn more: GitOps Architecture - GitOps Workflow


⚙️ Configuration

ArgoCD Settings

  • Reconciliation: Every 60 seconds
  • Sync timeout: 5 minutes per application
  • Retry policy: 5 attempts with exponential backoff
  • Authentication: Disabled (internal use only)

Application Defaults

  • Auto-sync: Enabled
  • Self-heal: Enabled
  • Prune: Enabled
  • Validation: Server-side validation enabled
  • Server-side apply: Enabled

Full configuration: Technical Reference - ArgoCD Configuration


🆘 Getting Help

Documentation

  1. Start here: Documentation Index
  2. For development: Developer Guide
  3. For operations: Operations Runbook
  4. For reference: Technical Reference

Support

  • Slack: #platform-support
  • Issues: Contact platform team
  • Emergencies: Escalate via Slack

Common Questions

Question Answer
How do I deploy an app? Developer Guide - Deploying Your First Application
How do I manage secrets? Developer Guide - Working with Secrets
App won't sync? Developer Guide - Troubleshooting
How do I bootstrap a cluster? Operations Runbook - Cluster Bootstrap
Where are the logs? Operations Runbook - Monitoring & Alerting

🤝 Contributing

Adding a New Application

  1. Read Developer Guide - Deploying Your First Application
  2. Create ArgoCD Application manifest in apps/
  3. Create Helm values in helm-prod-values/
  4. Create sealed secrets if needed
  5. Commit and push - ArgoCD handles the rest!

Modifying Infrastructure

  1. Read Operations Runbook
  2. Update relevant files in infra/ or cluster-resources/
  3. Test changes in isolated namespace if possible
  4. Commit and push
  5. Monitor sync status in Slack/ArgoCD UI

Updating Documentation

Documentation lives in docs/. To update:

  1. Edit relevant markdown file
  2. Update "Last Updated" date
  3. Submit PR or push directly
  4. Notify team of significant changes

📝 Notes

Current Environment

  • Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
  • Active clusters: UpCloud (upc-dev, upc-prod)
  • Environment: Production (internal use only)
  • Auth: Disabled for ArgoCD (internal access)
  • Backup: Gitea daily backup to S3-compatible storage

Known Limitations

  • Secret rotation not automated
  • DNS management is manual

Future improvements: See Operations Runbook - Disaster Recovery


📚 Additional Resources

External Documentation

  • forte-helm - Helm chart templates
  • helm-prod-values - Application values

📄 License

Internal use only. Not for public distribution.


👥 Maintainers

Platform Team

  • Contact: #platform-support on Slack
  • Issues: Create issue in repository or contact team directly

Last Updated: 2026-04-22 Documentation Version: 1.0.0

🚀 Ready to get started? Check out the Documentation Index!

S
Description
k8s launchpad
Readme
2.5 MiB
Languages
HCL 64.1%
Shell 35.9%