Skip to content

Latest commit

 

History

40 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dependency Track

Test Workflow Release Workflow The SLSA Level 3 badge The Apache 2.0 license badge Follow us on Bluesky

A Carvel package for Dependency Track, a continuous SBOM Analysis Platform for managing software supply chain security risks.

🚀  Getting Started

Prerequisites

  • Kubernetes 1.34+

  • Carvel kctrl CLI.

  • Carvel kapp-controller deployed in your Kubernetes cluster. You can install it with Carvel kapp (recommended choice) or kubectl.

    kapp deploy -a kapp-controller -y \
      -f https://github.com/carvel-dev/kapp-controller/releases/latest/download/release.yml

Dependencies

Dependency Track requires the following packages included in the Kadras Engineering Platform and available to install from the Kadras package repository:

Installation

Add the Kadras package repository to your Kubernetes cluster:

kctrl package repository add -r kadras-packages \
  --url ghcr.io/kadras-io/kadras-packages \
  -n kadras-system --create-namespace
Installation without package repository The recommended way of installing the Dependency Track package is via the Kadras package repository. If you prefer not using the repository, you can add the package definition directly using kapp or kubectl.
kubectl create namespace kadras-system
kapp deploy -a dependency-track-package -n kadras-system -y \
  -f https://github.com/kadras-io/package-for-dependency-track/releases/latest/download/metadata.yml \
  -f https://github.com/kadras-io/package-for-dependency-track/releases/latest/download/package.yml

Install the Dependency Track package:

kctrl package install -i dependency-track \
  -p dependency-track.packages.kadras.io \
  -v ${VERSION} \
  -n kadras-system

Note You can find the ${VERSION} value by retrieving the list of package versions available in the Kadras package repository installed on your cluster.

kctrl package available list -p dependency-track.packages.kadras.io -n kadras-system

Verify the installed packages and their status:

kctrl package installed list -n kadras-system

📙  Documentation

Documentation, tutorials and examples for this package are available in the docs folder. For documentation specific to Dependency Track, check out dependencytrack.org.

🎯  Configuration

The Dependency Track package can be customized via a values.yml file.

domain_name: "dependency-track.kadras.io"
ingress_issuer: "kadras-ca-issuer"
postgresql:
  instances: 3

Reference the values.yml file from the kctrl command when installing or upgrading the package.

kctrl package install -i dependency-track \
  -p dependency-track.packages.kadras.io \
  -v ${VERSION} \
  -n kadras-system \
  --values-file values.yml

Values

The Dependency Track package has the following configurable properties.

Configurable properties
Config Default Description
ca_cert_data "" PEM-encoded certificate data to trust TLS connections with a custom CA. It's imported into the Java truststore used by the API Server.
image.tag "" The tag to use for the API Server and Frontend container images, overriding the Dependency Track version bundled with this package. The images must be available in a container registry reachable from the cluster, since they are not part of the package bundle.
domain_name "" Domain name for Dependency Track. It must be a valid DNS name.
ingress_issuer "" A reference to the ClusterIssuer to use for enabling TLS in Dependency Track.

Settings for the API Server component.

Config Default Description
api_server.replicas 1 The number of API Server replicas. Values greater than 1 require a storage class supporting the ReadWriteMany access mode.
api_server.logging.level info Log verbosity level. Options: trace, debug, info, warn, error.
api_server.logging.format console Log encoding format. Options: console, json.
api_server.metrics.enabled true Whether to enable the generation of Prometheus metrics.
api_server.resources.requests.cpu 0.5 CPU requests configuration for the API Server component.
api_server.resources.requests.memory 5Gi Memory requests configuration for the API Server component.
api_server.resources.limits.cpu 4 CPU limits configuration for the API Server component.
api_server.resources.limits.memory 5Gi Memory limits configuration for the API Server component.
api_server.storage.class_name "" Class name for the PersistenceVolume to create.
api_server.storage.size 1Gi Size of the PersistenceVolume to create.
api_server.storage.access_modes ["ReadWriteOnce"] Access modes for the PersistenceVolume to create. ReadWriteMany is required when running more than one API Server replica.
api_server.config {} Additional configuration properties for the API Server, appended to the application.properties file and taking precedence over the ones managed by this package. See the properties reference for the full list.

Settings for the Frontend component.

Config Default Description
frontend.replicas 1 The number of Frontend replicas. In order to enable high availability, it should be greater than 1.
frontend.config {} Configuration for the Frontend, provided as environment variables. Use it to enable OpenID Connect, or to point the Frontend at an API Server served from a different host via API_BASE_URL.
frontend.resources.requests.cpu 150m CPU requests configuration for the Frontend component.
frontend.resources.requests.memory 64Mi Memory requests configuration for the Frontend component.
frontend.resources.limits.cpu 500m CPU limits configuration for the Frontend component.
frontend.resources.limits.memory 128Mi Memory limits configuration for the Frontend component.

Settings for the corporate proxy used by the API Server when calling external services.

Config Default Description
proxy.https_proxy "" The HTTPS proxy to use for network traffic. It must be a plain HTTP URL in the form http://[user[:password]@]host[:port].
proxy.http_proxy "" The HTTP proxy to use for network traffic. Used only when https_proxy is not configured. It must be a plain HTTP URL in the form http://[user[:password]@]host[:port].
proxy.no_proxy "" A comma-separated list of hostnames or IP addresses, optionally with a port, that should not use the proxy. An entry matches the host exactly or any of its subdomains. CIDR ranges and leading-dot notation are not supported.

Settings for the PostgreSQL database.

Config Default Description
postgresql.instances 1 Number of instances for the PostgreSQL database cluster. Define at least 3 for production scenarios.
postgresql.metrics.enabled true Whether to enable the generation of Prometheus metrics.
postgresql.storage.size 1Gi Size of the PersistenceVolume to create for each PostgreSQL instance.
postgresql.parameters {} Configuration parameters for the PostgreSQL server, merged on top of the ones recommended by Dependency Track (jit=off and wal_compression=zstd). Remember that max_connections must cover the sum of the connection pools of all the API Server replicas, plus headroom for migrations, backups, and administrator sessions.

🛡️  Security

The security process for reporting vulnerabilities is described in SECURITY.md.

🖊️  License

This project is licensed under the Apache License 2.0. See LICENSE for more information.

About

Kubernetes-native package for OWASP Dependency Track, a continuous SBOM Analysis Platform for managing software supply chain security risks.

Topics

Resources

Code of conduct

Security policy

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages