Skip to content

NVIDIA NVSentinel v1.19.0 - #303

Merged
kreeuwijk merged 7 commits into
mainfrom
nvidia-nvsentinel-1190
Aug 24, 2026
Merged

NVIDIA NVSentinel v1.19.0#303
kreeuwijk merged 7 commits into
mainfrom
nvidia-nvsentinel-1190

Conversation

@kreeuwijk

Copy link
Copy Markdown
Contributor

Latest version of NVIDIA NVSentinel v1.19.0
Now includes all images so it can be airgapped

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 27
  • Clean images: 27
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 19
  • Clean images: 1
  • Images with CVEs: 18
  • Total CVEs found: 6416

🔴 Critical CVEs: 235
🟠 High CVEs: 875
🟡 Medium CVEs: 938
🟢 Low CVEs: 4368

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 27
  • Clean images: 27
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 19
  • Clean images: 1
  • Images with CVEs: 18
  • Total CVEs found: 6420

🔴 Critical CVEs: 235
🟠 High CVEs: 874
🟡 Medium CVEs: 938
🟢 Low CVEs: 4373

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 27
  • Clean images: 27
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 19
  • Clean images: 1
  • Images with CVEs: 18
  • Total CVEs found: 6417

🔴 Critical CVEs: 235
🟠 High CVEs: 875
🟡 Medium CVEs: 938
🟢 Low CVEs: 4369

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 27
  • Clean images: 27
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 19
  • Clean images: 1
  • Images with CVEs: 18
  • Total CVEs found: 6417

🔴 Critical CVEs: 235
🟠 High CVEs: 876
🟡 Medium CVEs: 938
🟢 Low CVEs: 4368

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 35
  • Clean images: 35
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 27
  • Clean images: 1
  • Images with CVEs: 26
  • Total CVEs found: 9964

🔴 Critical CVEs: 333
🟠 High CVEs: 1512
🟡 Medium CVEs: 1522
🟢 Low CVEs: 6597

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ Combined scan completed with failures (conclusion: failure).

Secret Scan: No secrets detected

Scan Summary:

  • Total images scanned: 35
  • Clean images: 35
  • Images with secrets: 0

Please review the findings above and address any issues before merging.

@bulwark-sc-ent bulwark-sc-ent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ CVE scan completed successfully.

Scan Summary:

  • Total images scanned: 27
  • Clean images: 1
  • Images with CVEs: 26
  • Total CVEs found: 9965

🔴 Critical CVEs: 333
🟠 High CVEs: 1512
🟡 Medium CVEs: 1522
🟢 Low CVEs: 6598

Images with CVEs:

⚠️ Please review the CVE findings above and address critical/high severity issues before merging.

@vishwanaths

vishwanaths commented Aug 23, 2026

Copy link
Copy Markdown
Collaborator

Pack review — nvidia-nvsentinel-v1.19.0

Packs Validation: ❌ FAILURE (run 32267998150) — individual errors listed under Blockers below
source annotation: ✅ community
Pack metadata: name=nvidia-nvsentinel version=v1.19.0 addonType=ai layer=addon displayName=Nvidia NVSentinel contributor=spectrocloud

Compared against packs/nvidia-nvsentinel-v1.1.0/

Summary of differences

  • pack.json: patch-level fields only — .version bumped v1.1.0v1.19.0 and the referenced chart tarball updated to charts/nvsentinel-v1.19.0.tgz. No changes to name, displayName, addonType, layer, cloudTypes, or annotations.
  • values.yaml: substantial expansion (+192 / −27 lines). Notable changes:
    • pack.content.images: previously an empty list; now enumerates ~40 explicit image tags (all NVSentinel component images pinned to v1.19.0, plus bitnamilegacy/percona/etc. dependency images).
    • pack.releaseNameOverride: added entries csp-health-monitor, event-exporter, janitor-provider, k8sdatastore-crds, nic-health-monitor, slurm-drain-monitor (previously already had csp-health-monitor / event-exporter context but list restructured); reordered alphabetically.
    • charts.nvsentinel.global.image.tag: "v1.1.0""v1.19.0".
    • Documentation-heavy expansion of the (commented-out) datastore: block — adds guidance for external MongoDB/PostgreSQL, TLS, x509/scram auth, and a setup-job stanza. No functional default changes here (block remains commented).
    • DCGM section preamble reworded ("Shared by gpu-health-monitor and preflight dcgm-diag" → "Used by gpu-health-monitor").
  • README.md: +159 / −2 lines — largely expanded documentation for the new release.
  • charts/nvsentinel-<ver>.tgz: nvsentinel-v1.1.0.tgz (378,982 B) → nvsentinel-v1.19.0.tgz (417,347 B) — +38,365 B (+37.5 KiB, ~+10%). Tarball contents not inspected.
  • logo.png: unchanged (7,892 B in both versions).
  • Files added/removed: same top-level file set (README.md, charts/…tgz, logo.png, pack.json, values.yaml). No new/removed pack-level files.

pack.json diff

--- a/packs/nvidia-nvsentinel-v1.1.0/pack.json
+++ b/packs/nvidia-nvsentinel-v1.19.0/pack.json
@@ -9,9 +9,9 @@
     ],
     "displayName": "Nvidia NVSentinel",
     "charts": [
-      "charts/nvsentinel-v1.1.0.tgz"
+      "charts/nvsentinel-v1.19.0.tgz"
     ],
     "layer":"addon",
     "name": "nvidia-nvsentinel",
-    "version": "v1.1.0"
+    "version": "v1.19.0"
   }

values.yaml diff

Diff truncated — full file changed +192 / −27 lines; see the Files tab for the full view.

@@ -1,25 +1,75 @@
 pack:
   releaseNameOverride:
-    gpu-health-monitor: gpu-health-monitor
-    mongodb-store: mongodb-store
-    postgresql: postgresql
+    csp-health-monitor: csp-health-monitor
+    event-exporter: event-exporter
     fault-quarantine: fault-quarantine
-    node-drainer: node-drainer
     fault-remediation: fault-remediation
+    gpu-health-monitor: gpu-health-monitor
     health-events-analyzer: health-events-analyzer
-    csp-health-monitor: csp-health-monitor
-    syslog-health-monitor: syslog-health-monitor
     incluster-file-server: incluster-file-server
-    labeler: labeler
     janitor: janitor
-    metadata-collector: metadata-collector
+    janitor-provider: janitor-provider
+    k8sdatastore-crds: k8sdatastore-crds
     kubernetes-object-monitor: kubernetes-object-monitor
+    labeler: labeler
+    metadata-collector: metadata-collector
+    mongodb-store: mongodb-store
+    nic-health-monitor: nic-health-monitor
+    node-drainer: node-drainer
+    postgresql: postgresql
     preflight: preflight
+    slurm-drain-monitor: slurm-drain-monitor
+    syslog-health-monitor: syslog-health-monitor
   namespace: nvsentinel
   namespaceLabels:
     "nvsentinel": "pod-security.kubernetes.io/enforce=privileged,pod-security.kubernetes.io/enforce-version=latest"
   content:
-    images: []
+    images:
+      # ── NVIDIA nvsentinel components (v1.19.0)
+      - image: ghcr.io/nvidia/nvsentinel/platform-connectors:v1.19.0
+      - image: ghcr.io/nvidia/nvsentinel/csp-health-monitor:v1.19.0
+      ... (~40 image entries total; see Files tab) ...
@@
     global:
       dryRun: false
       image:
-        tag: "v1.1.0"
+        tag: "v1.19.0"

Blockers

  • Packs Validation: pack.json version must not have a leading 'v' (found: v1.19.0) in packs/nvidia-nvsentinel-v1.19.0/pack.json — the .version field must be a bare semver (1.19.0), not v1.19.0. The previous release (nvidia-nvsentinel-v1.1.0) used the same v-prefixed convention and now fails under the tightened validator; this release needs to drop the leading v in pack.json .version.

Nits / observations

  • The chart filename referenced in pack.json (charts/nvsentinel-v1.19.0.tgz) also carries a v prefix. That is not flagged by the validator (only the .version field is checked), but you may want to align the chart filename and the pack directory name with the bare semver once you drop the v from .version — otherwise the metadata and filesystem naming drift apart.
  • pack.content.images moved from empty ([]) to a fully enumerated list of ~40 pinned image tags. That is a great improvement for airgap/mirror workflows; just double-check that docker.io/lachlanevenson/k8s-kubectl:v1.25.4 (only image still using a v-prefixed tag) is intentional and matches what the chart references.
  • Line - image: ghcr.io/nvidia/nvsentinel/log-collector:v1.19.0 has a trailing space — harmless but easy to clean up.
  • The BulwarkGitLeaks / security-scans/pax-combined checks are also FAILURE on this PR (out of scope for pack-reviewer, but worth glancing at before requesting merge).

Review generated by the pack-reviewer Claude Code subagent.

vishwanaths
vishwanaths previously approved these changes Aug 24, 2026
…ers in nvidia-nvsentinel-v1.19.0

Add two fingerprints for the bundled psmdb-db chart's values.yaml. Both are
commented-out AWS S3/KMS backup config placeholders shipped by Percona:

  line 675: kmsKeyID: 1234abcd-12ab-34cd-56ef-1234567890ab
  line 678: sseCustomerKey: Y3VzdG9tZXIta2V5   (base64 for "customer-key")

Both are inert documentation examples inside upstream Percona chart defaults
and were flagged by the generic-api-key rule.

Unblocks the BulwarkGitLeaks check on #303.
@vishwanaths
vishwanaths dismissed bulwark-sc-ent[bot]’s stale review August 24, 2026 09:10

gitleaks changes have been incorporated

@kreeuwijk
kreeuwijk merged commit b12f63b into main Aug 24, 2026
4 of 5 checks passed
@kreeuwijk
kreeuwijk deleted the nvidia-nvsentinel-1190 branch August 24, 2026 13:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants