Install¶
Install from release¶
kubectl apply -f https://github.com/codenio/image-inventory-controller/releases/latest/download/install.yaml
Applies CRD, RBAC, Deployment (image-inventory-system), and NetworkPolicy. Controller image is pinned to the release tag on GHCR (ghcr.io/codenio/image-inventory-controller).
Pin a version (see Releases):
kubectl apply -f https://github.com/codenio/image-inventory-controller/releases/download/<version>/install.yaml
Prerequisites¶
| Requirement | Notes |
|---|---|
| Kubernetes | Compatible with clusters supporting client-go 0.31 APIs |
kubectl |
Context pointed at the target cluster |
| Permissions | Ability to install a CRD and ClusterRole |
Verify¶
kubectl -n image-inventory-system rollout status deploy/image-inventory-controller --timeout=120s
kubectl get crd images.imageinventory.io
kubectl get images -A
Demo workloads (from a clone of this repository):
Configuration¶
Controller flags (Deployment args):
| Flag | Default | Meaning |
|---|---|---|
--leader-elect |
true |
Single active reconciler |
--leader-elect-namespace |
image-inventory-system |
Namespace of the leader-election lease (must match RBAC) |
--metrics-bind-address |
127.0.0.1:8080 |
Metrics bind address |
--health-probe-bind-address |
:8081 |
/healthz (liveness), /readyz (cache synced) |
--namespaces |
"" (all) |
Comma-separated namespace filter for cache and reconcile |
Example — inventory only payments and platform:
With --namespaces set, only listed namespaces are inventoried. The shipped ClusterRole remains cluster-wide. Namespaces outside the list are not reconciled.
Tenant read access¶
Bind image-inventory-viewer with a RoleBinding in the tenant namespace. See Usage.
Install from source¶
git clone https://github.com/codenio/image-inventory-controller.git
cd image-inventory-controller
make verify
export IMG=image-inventory-controller:dev
make docker-build
# Load or push $IMG to the cluster registry, then:
make install
make install applies CRD + RBAC, Deployment, NetworkPolicy, then sets the controller image to $IMG.
Single-file bundle:
Manifests: config/crd/, config/rbac/, config/manager/, config/networkpolicy/.
Uninstall¶
Release install:
kubectl delete -f https://github.com/codenio/image-inventory-controller/releases/latest/download/install.yaml
From source:
| Artifact | After uninstall |
|---|---|
| Controller | Removed |
Image CRs |
Remain until deleted or the CRD is removed |
| CRD removal | Deletes all Image objects cluster-wide |
Remove managed inventory: