1
1
service_dir : ${ANCHORE_SERVICE_DIR}
2
2
tmp_dir : ${ANCHORE_TMP_DIR}
3
- log_level : ${ANCHORE_LOG_LEVEL}
3
+ log_level : ${ANCHORE_LOG_LEVEL} # Deprecated - prefer use of logging.log_level
4
+
5
+ logging :
6
+ {{- toYaml .Values.anchoreConfig.logging | nindent 2 }}
7
+
8
+ server :
9
+ {{- toYaml .Values.anchoreConfig.server | nindent 2 }}
4
10
5
11
allow_awsecr_iam_auto : ${ANCHORE_ALLOW_ECR_IAM_AUTO}
6
12
host_id : " ${ANCHORE_HOST_ID}"
@@ -19,6 +25,36 @@ max_import_content_size_mb: ${ANCHORE_MAX_IMPORT_CONTENT_SIZE_MB}
19
25
20
26
max_compressed_image_size_mb : ${ANCHORE_MAX_COMPRESSED_IMAGE_SIZE_MB}
21
27
28
+ audit :
29
+ enabled : {{ .Values.anchoreConfig.audit.enabled }}
30
+ mode : log
31
+ verbs :
32
+ - post
33
+ - put
34
+ - delete
35
+ - patch
36
+ resource_uris :
37
+ - " /accounts"
38
+ - " /accounts/{account_name}"
39
+ - " /accounts/{account_name}/state"
40
+ - " /accounts/{account_name}/users"
41
+ - " /accounts/{account_name}/users/{username}"
42
+ - " /accounts/{account_name}/users/{username}/api-keys"
43
+ - " /accounts/{account_name}/users/{username}/api-keys/{key_name}"
44
+ - " /accounts/{account_name}/users/{username}/credentials"
45
+ - " /rbac-manager/roles"
46
+ - " /rbac-manager/roles/{role_name}/members"
47
+ - " /rbac-manager/saml/idps"
48
+ - " /rbac-manager/saml/idps/{name}"
49
+ - " /rbac-manager/saml/idps/{name}/user-group-mappings"
50
+ - " /system/user-groups"
51
+ - " /system/user-groups/{group_uuid}"
52
+ - " /system/user-groups/{group_uuid}/roles"
53
+ - " /system/user-groups/{group_uuid}/users"
54
+ - " /user/api-keys"
55
+ - " /user/api-keys/{key_name}"
56
+ - " /user/credentials"
57
+
22
58
metrics :
23
59
enabled : ${ANCHORE_ENABLE_METRICS}
24
60
auth_disabled : ${ANCHORE_DISABLE_METRICS_AUTH}
@@ -45,7 +81,7 @@ user_authentication:
45
81
max_api_keys_per_user : {{ .Values.anchoreConfig.user_authentication.max_api_keys_per_user }}
46
82
remove_deleted_user_api_keys_older_than_days : {{ .Values.anchoreConfig.user_authentication.remove_deleted_user_api_keys_older_than_days }}
47
83
disallow_native_users : {{ .Values.anchoreConfig.user_authentication.disallow_native_users }}
48
-
84
+ log_saml_assertions : {{ .Values.anchoreConfig.user_authentication.log_saml_assertions }}
49
85
credentials :
50
86
database :
51
87
user : " ${ANCHORE_DB_USER}"
@@ -171,14 +207,10 @@ services:
171
207
data :
172
208
grypedb :
173
209
enabled : true
174
- url : {{ template "enterprise.grypeProviderURL" . }}
175
- packages :
176
- enabled : ${ANCHORE_FEEDS_DRIVER_PACKAGES_ENABLED}
177
- url : {{ template "enterprise.feedsURL" . }}
178
- vulnerability_annotations :
179
- enabled : ${ANCHORE_FEEDS_DRIVER_VULN_ANNOTATIONS_ENABLED}
180
- url : {{ template "enterprise.feedsURL" . }}
181
210
matching :
211
+ exclude :
212
+ providers : {{ .Values.anchoreConfig.policy_engine.vulnerabilities.matching.exclude.providers }}
213
+ package_types : {{ .Values.anchoreConfig.policy_engine.vulnerabilities.matching.exclude.package_types }}
182
214
default :
183
215
search :
184
216
by_cpe :
@@ -267,3 +299,19 @@ services:
267
299
ssl_enable : ${ANCHORE_SSL_ENABLED}
268
300
ssl_cert : ${ANCHORE_SSL_CERT}
269
301
ssl_key : ${ANCHORE_SSL_KEY}
302
+
303
+ data_syncer :
304
+ enabled : true
305
+ require_auth : true
306
+ endpoint_hostname : ${ANCHORE_ENDPOINT_HOSTNAME}
307
+ listen : 0.0.0.0
308
+ port : ${ANCHORE_PORT}
309
+ auto_sync_enabled : true
310
+ upload_dir : {{ .Values.scratchVolume.mountPath }}
311
+ datasets :
312
+ vulnerability_db :
313
+ versions : ["5"]
314
+ clamav_db :
315
+ versions : ["1"]
316
+ kev_db :
317
+ versions : ["1"]
0 commit comments