security-catalog 프로젝트에서 첫 실사용 자체 빌드 이미지 3종을 포팅한다 — 전부
상위 태그·베이스 OS 교체로 해소 안 되는 CVE(Go 모듈 정적 링크 또는 미수정 CRITICAL/
HIGH)를 자체 빌드(소스 컴파일 또는 SUSE BCI 재설치)로 대응한다:
- images/cloudnative-pg: CNPG operator, release-1.30 소스 컴파일 + bci-micro
- images/cnpg-postgresql: PostgreSQL 18.4, bci-base + zypper 재설치
- images/etcd: etcd v3.7.1, 소스 컴파일(x/text 강제 업그레이드) + bci-micro
함께 추가:
- manifests/helm/{cloudnative-pg,cnpg-cluster,etcd} — 위 이미지를 참조하는 카탈로그 차트
- scripts/deploy-test/*.sh, .claude/deploy-test-procedure.md — CVE 0건과 별개로
"실제로 뜨는가"를 검증하는 배포 스모크 테스트
- .claude/pitfalls.md — 자체 빌드/배포 테스트 중 실측한 함정 모음
검토 중 발견해 반영한 수정:
- cloudnative-pg 차트의 image 블록을 etcd와 동일한 registry/repository/tag 3필드+
따옴표 포맷으로 통일 — 기존 포맷(repository에 registry+repo 결합, 따옴표 없음)은
patch-catalog-tag.py 의 split 패처가 tag만 갱신하고 repository는 그대로 남기는
조용한 부분 치환을 일으켜, 향후 레지스트리 마이그레이션 시 깨진 참조를 만들 수 있었다
- cnpg-cluster 차트의 SLES 커버리지 코멘트를 최신 실측(trivy가 SLES 15.7을 정상
커버함, 2026-07-29 재측정)에 맞게 정정 — 폐기된 "측정 불가/OVAL 우회 필요" 결론이
남아있었다
- CLAUDE.md/MEMORY.md 의 "images/ 디렉토리 없음" 서술을 갱신하고, 레지스트리
마이그레이션(docker.io/wbsong111 → docker.io/paasup)·decisions/analysis 문서 이관·
리소스 프로파일 추가를 다음 작업으로 기록
이 3개 이미지는 아직 dip-catalog 자체 CI(build-image.yml)로 빌드·게이트·push 를
실행해본 적이 없다 — 현재 참조 태그는 security-catalog 쪽에서 이미 검증된 것이다.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
cloudnative-pg
CloudNativePG Operator Helm Chart
Homepage: https://cloudnative-pg.io
About this chart
Helm chart to install the CloudNativePG operator, originally created and sponsored by EDB to manage PostgreSQL workloads on any supported Kubernetes cluster running in private, public, or hybrid cloud environments.
NOTE: this chart supports only the latest point release of the CloudNativePG operator.
The chart installs only the operator (controller manager, webhooks, RBAC and CRDs). To provision a PostgreSQL
Cluster resource, use the companion cluster chart
(see the Cluster chart README for details)
or apply your own Cluster manifest.
Getting Started
Add the chart repository
helm repo add cnpg https://cloudnative-pg.github.io/charts
helm repo update
Install the operator
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
cnpg/cloudnative-pg
Install with custom parameters
You can override individual chart values from the command line with --set.
For example, to enable the Prometheus PodMonitor:
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
--set monitoring.podMonitorEnabled=true \
cnpg/cloudnative-pg
Note
Enabling the
PodMonitorrequires the Prometheus Operator CRDs to be installed in the cluster. Without them the install fails withno matches for kind "PodMonitor".
See the Values section below for the full list of configurable parameters.
Verify the installation
kubectl -n cnpg-system get deploy
kubectl -n cnpg-system rollout status deploy/cnpg-cloudnative-pg
Single namespace installation
It is possible to limit the operator's capabilities to solely the namespace in which it has been installed. With this restriction, the cluster-level permissions required by the operator will be substantially reduced, and the security profile of the installation will be enhanced.
You can install the operator in single-namespace mode by setting the config.clusterWide flag to false,
as in the following example:
helm upgrade --install cnpg \
--namespace cnpg-system \
--create-namespace \
--set config.clusterWide=false \
cnpg/cloudnative-pg
IMPORTANT: the single-namespace installation mode can't coexist with the cluster-wide operator. Otherwise there would be collisions when managing the resources in the namespace watched by the single-namespace operator. It is up to the user to ensure there is no collision between operators.
Uninstalling
helm uninstall cnpg --namespace cnpg-system
Warning
Uninstalling the chart does not remove the CRDs. Deleting them cascade-deletes every
Cluster(and other CloudNativePG) resource across the whole cluster, together with the PostgreSQL data stored in their PVCs. This is irreversible, so only delete the CRDs if you intend to permanently remove all managed databases.
Source Code
Requirements
Kubernetes: >=1.29.0-0
| Repository | Name | Version |
|---|---|---|
| https://cloudnative-pg.github.io/grafana-dashboards | monitoring(cluster) | 0.0 |
Values
| Key | Type | Default | Description |
|---|---|---|---|
| additionalArgs | list | [] |
Additional arguments to be added to the operator's args list. |
| additionalEnv | list | [] |
Array containing extra environment variables which can be templated. |
| affinity | object | {} |
Affinity for the operator to be installed. |
| commonAnnotations | object | {} |
Annotations to be added to all other resources. |
| config.clusterWide | bool | true |
This option determines if the operator is responsible for observing events across the entire Kubernetes cluster or if its focus should be narrowed down to the specific namespace within which it has been deployed. |
| config.create | bool | true |
Specifies whether the secret should be created. |
| config.data | object | {} |
The content of the configmap/secret, see https://cloudnative-pg.io/documentation/current/operator_conf/#available-options for all the available options. |
| config.maxConcurrentReconciles | int | 10 |
The maximum number of concurrent reconciles. Defaults to 10. |
| config.name | string | "cnpg-controller-manager-config" |
The name of the configmap/secret to use. |
| config.secret | bool | false |
Specifies whether it should be stored in a secret, instead of a configmap. |
| containerSecurityContext | object | {"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"readOnlyRootFilesystem":true,"runAsGroup":10001,"runAsUser":10001,"seccompProfile":{"type":"RuntimeDefault"}} |
Container Security Context. |
| crds.create | bool | true |
Specifies whether the CRDs should be created when installing the chart. |
| dnsPolicy | string | "" |
|
| fullnameOverride | string | "" |
|
| hostNetwork | bool | false |
|
| image.pullPolicy | string | "IfNotPresent" |
|
| image.repository | string | "ghcr.io/cloudnative-pg/cloudnative-pg" |
|
| image.tag | string | "" |
Overrides the image tag whose default is the chart appVersion. |
| imagePullSecrets | list | [] |
|
| monitoring.grafanaDashboard.annotations | object | {} |
Annotations that ConfigMaps can have to get configured in Grafana. |
| monitoring.grafanaDashboard.configMapName | string | "cnpg-grafana-dashboard" |
The name of the ConfigMap containing the dashboard. |
| monitoring.grafanaDashboard.create | bool | false |
|
| monitoring.grafanaDashboard.labels | object | {} |
Labels that ConfigMaps should have to get configured in Grafana. |
| monitoring.grafanaDashboard.namespace | string | "" |
Allows overriding the namespace where the ConfigMap will be created, defaulting to the same one as the Release. |
| monitoring.grafanaDashboard.sidecarLabel | string | "grafana_dashboard" |
Label that ConfigMaps should have to be loaded as dashboards. DEPRECATED: Use labels instead. |
| monitoring.grafanaDashboard.sidecarLabelValue | string | "1" |
Label value that ConfigMaps should have to be loaded as dashboards. DEPRECATED: Use labels instead. |
| monitoring.podMonitorAdditionalLabels | object | {} |
Additional labels for the podMonitor |
| monitoring.podMonitorEnabled | bool | false |
Specifies whether the monitoring should be enabled. Requires Prometheus Operator CRDs. |
| monitoring.podMonitorMetricRelabelings | list | [] |
Metrics relabel configurations to apply to samples before ingestion. |
| monitoring.podMonitorRelabelings | list | [] |
Relabel configurations to apply to samples before scraping. |
| monitoringQueriesConfigMap.name | string | "cnpg-default-monitoring" |
The name of the default monitoring configmap. |
| monitoringQueriesConfigMap.queries | string | `"backends:\n query: | \n SELECT sa.datname\n , sa.usename\n , sa.application_name\n , states.state\n , COALESCE(sa.count, 0) AS total\n , COALESCE(sa.max_tx_secs, 0) AS max_tx_duration_seconds\n FROM ( VALUES ('active')\n , ('idle')\n , ('idle in transaction')\n , ('idle in transaction (aborted)')\n , ('fastpath function call')\n , ('disabled')\n ) AS states(state)\n LEFT JOIN (\n SELECT datname\n , state\n , usename\n , COALESCE(application_name, '') AS application_name\n , pg_catalog.count(*)\n , COALESCE(EXTRACT (EPOCH FROM (pg_catalog.max(pg_catalog.now() OPERATOR(pg_catalog.-) xact_start))), 0) AS max_tx_secs\n FROM pg_catalog.pg_stat_activity\n GROUP BY datname, state, usename, application_name\n ) sa ON states.state OPERATOR(pg_catalog.=) sa.state\n WHERE sa.usename IS NOT NULL\n metrics:\n - datname:\n usage: "LABEL"\n description: "Name of the database"\n - usename:\n usage: "LABEL"\n description: "Name of the user"\n - application_name:\n usage: "LABEL"\n description: "Name of the application"\n - state:\n usage: "LABEL"\n description: "State of the backend"\n - total:\n usage: "GAUGE"\n description: "Number of backends"\n - max_tx_duration_seconds:\n usage: "GAUGE"\n description: "Maximum duration of a transaction in seconds"\n\nbackends_waiting:\n query: |
| nameOverride | string | "" |
|
| namespaceOverride | string | "" |
|
| nodeSelector | object | {} |
Nodeselector for the operator to be installed. |
| podAnnotations | object | {} |
Annotations to be added to the pod. |
| podLabels | object | {} |
Labels to be added to the pod. |
| podSecurityContext | object | {"runAsNonRoot":true,"seccompProfile":{"type":"RuntimeDefault"}} |
Security Context for the whole pod. |
| priorityClassName | string | "" |
Priority indicates the importance of a Pod relative to other Pods. |
| rbac.aggregateClusterRoles | bool | false |
Aggregate ClusterRoles to Kubernetes default user-facing roles. Ref: https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles |
| rbac.create | bool | true |
Specifies whether ClusterRole and ClusterRoleBinding should be created. |
| replicaCount | int | 1 |
|
| resources | object | {} |
|
| service.ipFamilies | list | [] |
Sets the families that should be supported and the order in which they should be applied to ClusterIP as well. Can be IPv4 and/or IPv6. |
| service.ipFamilyPolicy | string | "" |
Set the ip family policy to configure dual-stack see Configure dual-stack |
| service.name | string | "cnpg-webhook-service" |
The name of the Webhook Service. |
| service.port | int | 443 |
|
| service.type | string | "ClusterIP" |
|
| serviceAccount.create | bool | true |
Specifies whether the service account should be created. |
| serviceAccount.name | string | "" |
The name of the service account to use. If not set and create is true, a name is generated using the fullname template. |
| tolerations | list | [] |
Tolerations for the operator to be installed. |
| topologySpreadConstraints | list | [] |
Topology Spread Constraints for the operator to be installed. |
| updateStrategy | object | {} |
Update strategy for the operator. ref: https://kubernetes.io/docs/concepts/workloads/controllers/deployment/#strategy |
| webhook | object | {"livenessProbe":{"initialDelaySeconds":3},"mutating":{"create":true,"failurePolicy":"Fail"},"port":9443,"readinessProbe":{"initialDelaySeconds":3},"startupProbe":{"failureThreshold":6,"periodSeconds":5},"validating":{"create":true,"failurePolicy":"Fail"}} |
The webhook configuration. |
Maintainers
| Name | Url | |
|---|---|---|
| phisco | p.scorsolini@gmail.com |
Contributing
Please read the code of conduct and the guidelines to contribute to the project.
Copyright
Helm charts for CloudNativePG are distributed under Apache License 2.0.