sse-secure-systems/connaisseur
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
GoApache-2.0
Issues
- 0
- 1
Not able to Deploy Connaisseur
#1802 opened by sjain700 - 6
Using cosign validation works for about 6 hours and then we start getting validation errors for Connaisseur application version 3.6.1 and chart version 2.6.1
#1765 opened by edison-vflow - 1
- 2
Documentation Error : : Using Sigstore / Cosign validation with 'auth.k8sKeychain.true' for Connaisseur from application version 3.6.0 and chart version 2.6.0 is broken
#1766 opened by edison-vflow - 2
Redis logs have errors using the default values.yaml from application version 3.6.0 chart version 2.6.0
#1764 opened by edison-vflow - 3
Passing in kubernetes.deployment.envs to connaisseur chart values for chart version 2.4 upwards breaks helm deployment
#1734 opened by edison-vflow - 2
- 3
- 2
Failed calling webhook
#1221 opened by rkydx - 0
- 2
- 3
Duplicate MutatingWebhookConfiguration
#1665 opened by graipher - 4
- 0
Cosign Certificates Issues with version 3.4.0/3.5.0
#1640 opened by burrmit - 2
enable redis as optional feature
#1587 opened by tomfankhaenel - 12
Slow memory leak causing cosign subprocess termination
#1090 opened by sbeck14 - 8
SSLV3_ALERT_BAD_CERTIFICATE: failed calling webhook "connaisseur-svc.connaisseur.svc":
#1168 opened by kgopi1 - 6
Connaisseur verifies signature with every helm reconcile even with automaticUnchangedApproval enabled
#1203 opened by dbbhat - 0
Streamline config handling
#1592 opened by Starkteetje - 20
- 3
Feature request: Allow for adding custom labels to the deployment manifest of the helm chart
#1487 opened by jimonthebarn - 17
Better support for gitops based approaches
#1220 opened by dbbhat - 0
Broken policy pattern regex
#1404 opened by Starkteetje - 4
Does Connaisseur have caching mechanism that prevents repeat verification of an image?
#1536 opened by qx121 - 2
- 0
"successful verification of image" log missing
#1524 opened by qx121 - 2
Option for HTML escaping of alert messages
#1518 opened by Starkteetje - 0
- 0
Add capability to enable hostNetwork
#1318 opened by pranali139 - 0
adapt documentation for GKE firewall rule
#1436 opened by phbelitz - 0
Dependabot updates not for all actions
#1438 opened by Starkteetje - 0
Look into OpenPubkey
#1476 opened by Starkteetje - 3
error converting YAML to JSON
#1399 opened by samispurs - 1
More logging around cosign signature verification
#1236 opened by dbbhat - 0
Helm chart: Explicitly describe the exposed port
#1305 opened by hsudbrock - 2
- 0
A pod with an unsigned image can't be deleted
#1224 opened by dzanto - 1
Helm Chart: Allow to configure the pod security context
#1240 opened by hsudbrock - 0
- 2
Connaisseur should stop checking trusted roots after meeting threshold of valid answers
#977 opened by shani-e - 1
cosign use private registries and self-signed certificate get error “ error converting YAML to JSON: yaml “ though helm install
#1114 opened by sunnoy - 3
Support Cosign 2.0
#918 opened by xopham - 0
- 1
Update Connaisseur logs to JSON format
#976 opened by shani-e - 0
"hasConfigSecrets" at <not>: wrong number of args for not: want 1 got 0 with auth username and password
#1084 opened by markrzasa - 10
ArgoCD Detects duplicate resource
#1103 opened by kgopi1 - 2
Please cut and release a new version
#1067 opened by richgerrard - 0
Tracking issue: CI refactoring
#914 opened by xopham - 0
Protect GHCR releases
#915 opened by xopham