diff --git a/clusters/cl01tl/helm/trivy/values.yaml b/clusters/cl01tl/helm/trivy/values.yaml index f0a4a29ac..7a8e4fcfc 100644 --- a/clusters/cl01tl/helm/trivy/values.yaml +++ b/clusters/cl01tl/helm/trivy/values.yaml @@ -2,13 +2,13 @@ trivy-operator: targetWorkloads: "pod,replicaset,replicationcontroller,statefulset,daemonset,cronjob,job" operator: replicas: 1 - scanJobsConcurrentLimit: 3 + scanJobsConcurrentLimit: 1 vulnerabilityScannerEnabled: true - sbomGenerationEnabled: true - clusterSbomCacheEnabled: true + sbomGenerationEnabled: false + clusterSbomCacheEnabled: false configAuditScannerEnabled: true rbacAssessmentScannerEnabled: true - infraAssessmentScannerEnabled: true + infraAssessmentScannerEnabled: false clusterComplianceEnabled: false vulnerabilityScannerScanOnlyCurrentRevisions: true accessGlobalSecretsAndServiceAccount: true @@ -47,6 +47,10 @@ trivy-operator: memory: 512Mi replicas: 1 nodeCollector: + tolerations: + - key: node-role.kubernetes.io/control-plane + operator: Exists + effect: NoSchedule volumeMounts: - name: var-lib-etcd mountPath: /var/lib/etcd