diff --git a/clusters/cl01tl/services/eraser/Chart.yaml b/clusters/cl01tl/services/eraser/Chart.yaml new file mode 100644 index 000000000..dca2a418c --- /dev/null +++ b/clusters/cl01tl/services/eraser/Chart.yaml @@ -0,0 +1,20 @@ +apiVersion: v2 +name: eraser +version: 1.0.0 +description: Eraser +keywords: + - eraser + - images + - kubernetes +home: https://wiki.alexlebens.dev/doc/eraser-XPOB4BLlm7 +sources: + - https://github.com/eraser-dev/eraser + - https://github.com/eraser-dev/eraser/tree/main/charts/eraser +maintainers: + - name: alexlebens +dependencies: + - name: eraser + version: v1.3.1 + repository: https://eraser-dev.github.io/eraser/charts +icon: https://raw.githubusercontent.com/walkxcode/dashboard-icons/main/png/kubernetes.png +appVersion: v1.3.1 diff --git a/clusters/cl01tl/services/eraser/values.yaml b/clusters/cl01tl/services/eraser/values.yaml new file mode 100644 index 000000000..8c4b2a009 --- /dev/null +++ b/clusters/cl01tl/services/eraser/values.yaml @@ -0,0 +1,70 @@ +eraser: + runtimeConfig: + apiVersion: eraser.sh/v1alpha3 + kind: EraserConfig + manager: + runtime: + name: containerd + address: unix:///run/containerd/containerd.sock + logLevel: info + scheduling: + repeatInterval: 24h + beginImmediately: true + profile: + enabled: false + port: 6060 + imageJob: + successRatio: 1.0 + cleanup: + delayOnSuccess: 0s + delayOnFailure: 24h + nodeFilter: + type: exclude + selectors: + - eraser.sh/cleanup.filter + - kubernetes.io/os=windows + components: + collector: + enabled: true + request: + cpu: 100m + memory: 128Mi + scanner: + enabled: false + request: + cpu: 100m + memory: 128Mi + config: "" # | + # cacheDir: /var/lib/trivy + # dbRepo: ghcr.io/aquasecurity/trivy-db + # deleteFailedImages: true + # deleteEOLImages: true + # vulnerabilities: + # ignoreUnfixed: true + # types: + # - os + # - library + # securityChecks: + # - vuln + # severities: + # - CRITICAL + # - HIGH + # - MEDIUM + # - LOW + # ignoredStatuses: + # timeout: + # total: 23h + # perImage: 1h + remover: + request: + cpu: 100m + memory: 128Mi + deploy: + securityContext: + allowPrivilegeEscalation: false + resources: + requests: + cpu: 100m + memory: 30Mi + nodeSelector: + kubernetes.io/os: linux