aquasecurity/trivy

Support for CRI-O

Open

#3,004 opened on Oct 9, 2022

View on GitHub
 (3 comments) (0 reactions) (0 assignees)Go (35,000 stars) (371 forks)batch import
help wantedkind/featurepriority/backlog

Description

We are building an image-scanner K8s-operator, and all our clusters runs Openshift. Inspired by trivy-operator, which we cannot use for various reasons, we schedule scan jobs to scan container images currently in use by workloads in the cluster.

While the operator works, it could be optimized if trivy supported CRI-O, which is the CRI implementation that Openshift uses. This would allow us to scan the image pulled from the nodes image registry, by scheduling the scan job on the node that runs the pod in question.

Related issues: https://github.com/aquasecurity/trivy/issues/1282, https://github.com/aquasecurity/trivy/issues/851, https://github.com/aquasecurity/trivy-operator/issues/101

Contributor guide

Support for CRI-O · aquasecurity/trivy#3004 | Good First Issue