Is there a way to disable Trivy integration in Tanzu Hub?
search cancel

Is there a way to disable Trivy integration in Tanzu Hub?

book

Article ID: 436008

calendar_today

Updated On:

Products

VMware Tanzu Platform - Hub

Issue/Introduction

Is there a way to disable Trivy integration into Hub?

This is in reference to setting "Tanzu Hub > Advanced Settings > Trivy Database Registry Location".

Resolution

Trivy cannot be disabled, but you can point it at the internal registry so that it does not need any external resource at all (Internet or internal registry).

Enter an internal registry for the configuration setting: "Tanzu Hub > Advanced Settings > Trivy Database Registry Location"

Reference Hub Install documentation

If your environment is Internet restricted or air-gapped, move the Trivy scanner database image to an image registry accessible to Tanzu Hub and configure the new location in the Tanzu Hub tile.

The Tanzu Hub tile image includes a Trivy database snapshot to simplify the configuration in air-gapped environments.

In Tanzu Operations Manager, enter the internal location of the database:

registry.internal:10500/hub-self-managed/repo/aquasecurity/trivy-db:embedded

Select Allow Insecure Registry Connections as this registry uses a self-signed certificate.