Files
service-catalog/manifests/helm/kyverno/3.8.2/charts/reports-server
wbsong111 16321b52c7 dipup 사용 차트를 카탈로그에 동기화 (7개 갱신 + 5개 신규)
dipup 이 go:embed 로 직접 보관·관리하던 Helm 차트를 카탈로그로 옮기는 첫 단계다.
두 저장소가 각자 CVE/SBOM 파이프라인을 운영하는 이중화를 해소하려면, 먼저 카탈로그가
dipup 과 같은 차트·같은 이미지를 보게 만들어야 한다.

배경: CVE 파이프라인 구성 이전에 두 곳에서 같은 차트를 유지하기 어려워 dipup 이 별도로
차트를 관리해 왔고, 그 결과 버전이 갈라졌다. 겹치는 10개 중 버전까지 일치하는 것은
postgresql-ha·dnsup 2개뿐이었다.

## 버전 갱신 (7개) — 신규 버전 디렉토리 추가, 구버전은 보존

| 차트 | 기존 | 신규 | appVersion |
|---|---|---|---|
| apisix | 2.14.0 | 2.16.0 | 3.16.0 → 3.17.0 |
| argo-cd | 7.7.0 | 7.8.11 | v2.13.0 → v2.14.5 |
| cert-manager | v1.16.1 | v1.21.0 | 동일 |
| gitea | 12.4.0 | 12.6.0 | 1.24.6 → 1.26.1 |
| harbor | 1.16.2 | 1.19.1 | 2.12.2 → 2.15.1 |
| kyverno | 3.4.1 | 3.8.2 | v1.14.1 → v1.18.2 |
| rancher | 2.10.1 | 2.14.3 | v2.10.1 → v2.14.3 |

차트 본문은 dipup 이 임베딩한 .tgz 를 그대로 전개했다(네트워크 pull 이 아니라 dipup 이
실제 배포하는 바이트와 동일함을 보장하기 위함). BUILD-README/CUSTOM-README/custom-values
3개 파일은 구버전에서 승계했다.

## 신규 추가 (5개)

infisical-standalone 1.9.0, longhorn 109.3.1+up1.11.2, longhorn-crd 109.3.1+up1.11.2,
metallb 0.16.1, secrets-operator v0.10.33.

longhorn/longhorn-crd 는 업스트림이 아니라 Rancher 패키징 차트(109.x 라인, Rancher 2.14
계열과 짝)다. BUILD-README 의 `helm repo add` 라인은 chart_version_detector 가 파싱하는
계약이라 실제 업스트림 repo 를 검증해 기재했고, 감지기로 현재/최신 버전이 정상 조회되는
것을 확인했다.

## custom-values — 버전과 결합된 이미지 핀 정리

카탈로그 스캐너가 dipup 의 effective image 를 보게 하려면 이미지 핀이 맞아야 한다.

- **kyverno: 승계본이 3.8.2 에서 깨져 재작성.** 3.4.1 은 정리 훅이
  `registry: ~ / repository: bitnami/kubectl` 이라 bitnamilegacy 오버라이드가 맞았지만,
  3.8.2 는 `registry: ghcr.io / repository: kyverno/readiness-checker` 로 바뀌었다.
  그대로 옮기면 ghcr.io/bitnamilegacy/kubectl 이라는 없는 좌표가 된다. 해당 오버라이드를
  제거하고, 3.8.2 에서 삭제된 policyReportsCleanup 키도 함께 뺐다. 남는 조치는 tag 고정뿐
  (기본 tag 가 비어 latest 로 떨어짐 → v1.18.2 로 고정).
- apisix: 3.16.0-keycloak-authz → 3.17.0-keycloak-authz (차트 appVersion 과 함께 이동)
- gitea: image.tag 1.26.4 핀 추가 — 차트 기본 1.26.1 대비 CRITICAL 2→0, HIGH 44→12
- infisical: image.tag v0.162.7 핀 — 기본 v0.158.x 는 stale Debian base 로 OS 기인 CVE
  다수(fixable CRITICAL 53→5, HIGH 491→55). redis/postgresql 은 bitnamilegacy 좌표로.
- longhorn: 실측 기반 리소스 튜닝(manager request, guaranteedInstanceManagerCPU,
  systemManagedCSIComponentsResourceLimits). replica 수처럼 노드 수에 의존하는 값은
  넣지 않았다 — 소비 측에서 주입한다.

## 검증

12개 차트 전부 `helm template --kube-version 1.34.1` 렌더 성공. 렌더 결과 이미지가
dipup 배포 이미지와 일치함을 확인(paasup/apisix:3.17.0-keycloak-authz,
gitea:1.26.4-rootless, readiness-checker:v1.18.2, infisical:v0.162.7).

## 범위에서 뺀 것

- **keycloak**: 카탈로그는 codecentric(app 17.0.1-legacy), dipup 은 bitnami(app 26.2.4)로
  계보가 다르다. 이슈 #1(bitnami 대체 방안 검토)의 결론이 나온 뒤 처리한다.
- **rancher-monitoring(-crd)**: 14c05f1 에서 불필요 판단으로 제거된 차트이고
  victoria-metrics 스택으로 대체 예정이라 추가하지 않는다.
- **dip-api/dip-console**: 자체 개발 차트로 각 앱 저장소가 출처다. 대조 결과 앱 저장소와
  dipup 사본이 일치해 카탈로그가 개입할 이유가 없다.
- **postgresql-ha/dnsup**: 이미 버전이 일치해 작업 대상이 아니었다.

## 후속 과제

dnsup 은 카탈로그·dipup 사본(1.0.1)이 원본(dip-console-api helm/dnsup 1.0.0)보다 앞서
있다. 1.0.1 에만 있는 service.LoadBalancerIP·service.annotations 지원을 원본으로 백포트한
뒤, 카탈로그에서 dnsup 을 제거하는 것이 자체 개발 차트 출처 원칙에 맞다.
2026-08-06 09:42:24 +09:00
..

reports-server

Version: 0.1.6 Type: application AppVersion: v0.1.6

TODO

Installing the Chart

Add reports-server Helm repository:

helm repo add reports-server https://kyverno.github.io/reports-server/

Install reports-server Helm chart:

helm install reports-server --namespace reports-server --create-namespace reports-server/reports-server

Values

Key Type Default Description
postgresql.image.registry string "docker.io"
postgresql.image.repository string "bitnamilegacy/postgresql"
postgresql.image.tag string "16.1.0-debian-11-r22"
postgresql.image.digest string ""
postgresql.enabled bool true Deploy postgresql dependency chart
postgresql.auth.postgresPassword string "reports"
postgresql.auth.database string "reportsdb"
nameOverride string "" Name override
fullnameOverride string "" Full name override
replicaCount int 1 Number of pod replicas
clusterName string "" Optional cluster name, used to easily identify database records when querying the database directly
image.registry string "ghcr.io" Image registry
image.repository string "kyverno/reports-server" Image repository
image.pullPolicy string "IfNotPresent" Image pull policy
image.tag string nil Image tag (will default to app version if not set)
imagePullSecrets list [] Image pull secrets
priorityClassName string "system-cluster-critical" Priority class name
serviceAccount.create bool true Create service account
serviceAccount.annotations object {} Service account annotations
serviceAccount.name string "" Service account name (required if serviceAccount.create is false)
podAnnotations object {} Pod annotations
commonLabels object {} Labels to add to resources managed by the chart
podSecurityContext object {"fsGroup":2000} Pod security context
podEnv object {} Provide additional environment variables to the pods. Map with the same format as kubernetes deployment spec's env.
securityContext object See values.yaml Container security context
livenessProbe object {"failureThreshold":10,"httpGet":{"path":"/livez","port":"https","scheme":"HTTPS"},"initialDelaySeconds":20,"periodSeconds":10} Liveness probe
readinessProbe object {"failureThreshold":10,"httpGet":{"path":"/readyz","port":"https","scheme":"HTTPS"},"initialDelaySeconds":30,"periodSeconds":10} Readiness probe
metrics.enabled bool true Enable prometheus metrics
metrics.serviceMonitor.enabled bool false Enable service monitor for scraping prometheus metrics
metrics.serviceMonitor.additionalLabels object {} Service monitor additional labels
metrics.serviceMonitor.interval string "" Service monitor scrape interval
metrics.serviceMonitor.metricRelabelings list [] Service monitor metric relabelings
metrics.serviceMonitor.relabelings list [] Service monitor relabelings
metrics.serviceMonitor.scrapeTimeout string "" Service monitor scrape timeout
resources.limits string nil Container resource limits
resources.requests string nil Container resource requests
autoscaling.enabled bool false Enable autoscaling
autoscaling.minReplicas int 1 Min number of replicas
autoscaling.maxReplicas int 100 Max number of replicas
autoscaling.targetCPUUtilizationPercentage int 80 Target CPU utilisation
autoscaling.targetMemoryUtilizationPercentage string nil Target Memory utilisation
pdb object {"enabled":true,"maxUnavailable":"50%","minAvailable":null} Using a PDB is highly recommended for highly available deployments. Defaults to enabled. The default configuration doesn't prevent disruption when using a single replica
pdb.enabled bool true Enable PodDisruptionBudget
pdb.minAvailable string nil minAvailable pods for PDB, cannot be used together with maxUnavailable
pdb.maxUnavailable string "50%" maxUnavailable pods for PDB, will take precedence over minAvailable if both are defined
nodeSelector object {} Node selector
tolerations list [] Tolerations
affinity object {} Affinity
service.type string "ClusterIP" Service type
service.port int 443 Service port
config.etcd.enabled bool false
config.etcd.endpoints string nil
config.etcd.insecure bool true
config.db.secretName string "" If set, database connection information will be read from the Secret with this name. Overrides db.host, db.name, db.user, and db.password.
config.db.host string "" Database host
config.db.hostSecretKeyName string "host" The database host will be read from this key in the specified Secret, when db.secretName is set.
config.db.port int 5432 Database port
config.db.portSecretKeyName string "port" The database port will be read from this key in the specified Secret, when db.secretName is set.
config.db.name string "reportsdb" Database name
config.db.dbNameSecretKeyName string "dbname" The database name will be read from this key in the specified Secret, when db.secretName is set.
config.db.user string "postgres" Database user
config.db.userSecretKeyName string "username" The database username will be read from this key in the specified Secret, when db.secretName is set.
config.db.password string "reports" Database password
config.db.passwordSecretKeyName string "password" The database password will be read from this key in the specified Secret, when db.secretName is set.
config.db.sslmode string "disable" Database SSL
config.db.sslrootcert string "" Database SSL root cert
config.db.sslkey string "" Database SSL key
config.db.sslcert string "" Database SSL cert
apiServicesManagement.enabled bool true Create a helm hooks to delete api services on uninstall
apiServicesManagement.installApiServices object {"enabled":true,"installEphemeralReportsService":true,"installOpenreportsService":true} Install api services in manifest
apiServicesManagement.installApiServices.enabled bool true Store reports in reports-server
apiServicesManagement.installApiServices.installEphemeralReportsService bool true Store ephemeral reports in reports-server
apiServicesManagement.installApiServices.installOpenreportsService bool true Store open reports in reports-server
apiServicesManagement.image.registry string "docker.io" Image registry
apiServicesManagement.image.repository string "bitnamilegacy/kubectl" Image repository
apiServicesManagement.image.tag string "1.30.2" Image tag Defaults to latest if omitted
apiServicesManagement.image.pullPolicy string nil Image pull policy Defaults to image.pullPolicy if omitted
apiServicesManagement.imagePullSecrets list [] Image pull secrets
apiServicesManagement.podSecurityContext object {} Security context for the pod
apiServicesManagement.nodeSelector object {} Node labels for pod assignment
apiServicesManagement.tolerations list [] List of node taints to tolerate
apiServicesManagement.podAntiAffinity object {} Pod anti affinity constraints.
apiServicesManagement.podAffinity object {} Pod affinity constraints.
apiServicesManagement.podLabels object {} Pod labels.
apiServicesManagement.podAnnotations object {} Pod annotations.
apiServicesManagement.nodeAffinity object {} Node affinity constraints.
apiServicesManagement.securityContext object {"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"privileged":false,"readOnlyRootFilesystem":true,"runAsGroup":65534,"runAsNonRoot":true,"runAsUser":65534,"seccompProfile":{"type":"RuntimeDefault"}} Security context for the hook containers
extraObjects list []

Source Code

Requirements

Kubernetes: >=1.16.0-0

Repository Name Version
oci://registry-1.docker.io/bitnamicharts postgresql 13.4.1

Maintainers

Name Email Url
Nirmata cncf-kyverno-maintainers@lists.cncf.io https://kyverno.io/

Autogenerated from chart metadata using helm-docs v1.11.0