Add nvidia-vss-data-infrastructure 3.3.2 (NVIDIA VSS Blueprint 3.1.0)#240
Add nvidia-vss-data-infrastructure 3.3.2 (NVIDIA VSS Blueprint 3.1.0)#240blik616287 wants to merge 7 commits into
Conversation
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 6
- Clean images: 0
- Images with CVEs: 6
- Total CVEs found: 1723
🔴 Critical CVEs: 55
🟠 High CVEs: 185
🟡 Medium CVEs: 255
🟢 Low CVEs: 1228
Images with CVEs:
- arizephoenix/phoenix:version-8.12.1: 283 CVEs (Critical: 8, High: 34, Medium: 50, Low: 191)
Critical CVEs: CVE-2019-1010022, CVE-2023-45853, CVE-2025-6965, CVE-2025-7458, CVE-2026-31789, CVE-2026-7210 - confluentinc/cp-kafka:8.1.1: 422 CVEs (Critical: 13, High: 50, Medium: 77, Low: 282)
Critical CVEs: CVE-2025-14087, CVE-2025-68121, CVE-2026-2332, CVE-2026-27143, CVE-2026-31789, CVE-2026-33845, CVE-2026-42010, CVE-2026-7210 - docker.elastic.co/kibana/kibana:9.3.0: 455 CVEs (Critical: 15, High: 46, Medium: 80, Low: 314)
Critical CVEs: CVE-2025-14087, CVE-2025-62718, CVE-2025-68665, CVE-2026-1525, CVE-2026-27699, CVE-2026-31789, CVE-2026-33845, CVE-2026-42010, CVE-2026-42043, CVE-2026-42044, CVE-2026-42264, CVE-2026-4800, CVE-2026-7210 - docker.elastic.co/logstash/logstash:9.3.0: 350 CVEs (Critical: 13, High: 37, Medium: 41, Low: 259)
Critical CVEs: CVE-2025-14087, CVE-2026-31789, CVE-2026-33845, CVE-2026-42010, CVE-2026-42257, CVE-2026-42258, CVE-2026-42581, CVE-2026-42584 - postgres:17.6-alpine: 130 CVEs (Critical: 4, High: 13, Medium: 6, Low: 107)
Critical CVEs: CVE-2025-68121, CVE-2026-27143, CVE-2026-31789 - redis:8.2.2-alpine: 83 CVEs (Critical: 2, High: 5, Medium: 1, Low: 75)
Critical CVEs: CVE-2026-31789
redis/postgres -> cgr.dev/chainguard (0/0); phoenix (chainguard/python + pip arize-phoenix) and ES (chainguard/wolfi-base + apk openjdk + tarball) provisioned at deploy. content.images all public 0/0; pack-central validator content-image pull passes (no gated exception). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 4
- Clean images: 2
- Images with CVEs: 2
- Total CVEs found: 8
🔴 Critical CVEs: 1
🟠 High CVEs: 0
🟡 Medium CVEs: 1
🟢 Low CVEs: 6
Images with CVEs:
- cgr.dev/chainguard/python:latest-dev: 7 CVEs (Critical: 1, High: 0, Medium: 1, Low: 5)
Critical CVEs: CVE-2026-7210 - cgr.dev/chainguard/redis:latest: 1 CVEs (Critical: 0, High: 0, Medium: 0, Low: 1)
…026-7210) python:latest-dev carries a fresh Critical (CVE-2026-7210) in its dev toolchain. Switch phoenix to the 0/0 wolfi-base + runtime apk python-3.12/py3.12-pip (validated on GB10: Python 3.12.13, arize-phoenix serves on 6006). content.images now redis/postgres/wolfi-base, all 0/0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 3
- Clean images: 2
- Images with CVEs: 1
- Total CVEs found: 1
🔴 Critical CVEs: 0
🟠 High CVEs: 0
🟡 Medium CVEs: 0
🟢 Low CVEs: 1
Images with CVEs:
- cgr.dev/chainguard/redis:latest: 1 CVEs (Critical: 0, High: 0, Medium: 0, Low: 1)
✅ All scanned images have only low severity CVEs (1 total).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 3
- Clean images: 2
- Images with CVEs: 1
- Total CVEs found: 1
🔴 Critical CVEs: 0
🟠 High CVEs: 0
🟡 Medium CVEs: 0
🟢 Low CVEs: 1
Images with CVEs:
- cgr.dev/chainguard/redis:latest: 1 CVEs (Critical: 0, High: 0, Medium: 0, Low: 1)
✅ All scanned images have only low severity CVEs (1 total).
…-infrastructure-3.2.0
Replaces 3.3.0 with the 3.3.2 pack validated running on a GB10 (DGX Spark) edge cluster: Elasticsearch and Phoenix runtime-provisioned on public Chainguard/wolfi-base images (0 Critical/0 High CVEs), bundled-JDK launcher, single-node discovery, hardened readiness/liveness probes; redis/postgres re-based to Chainguard with fsGroup. Merged upstream/main (picks up the crane-manifest validator fix). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 4
- Clean images: 2
- Images with CVEs: 2
- Total CVEs found: 8
🔴 Critical CVEs: 1
🟠 High CVEs: 0
🟡 Medium CVEs: 1
🟢 Low CVEs: 6
Images with CVEs:
- cgr.dev/chainguard/python:latest-dev: 7 CVEs (Critical: 1, High: 0, Medium: 1, Low: 5)
Critical CVEs: CVE-2026-7210 - cgr.dev/chainguard/redis:latest: 1 CVEs (Critical: 0, High: 0, Medium: 0, Low: 1)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
CVE-2026-7210 (phoenix runtime base) — why it's not remediated here, and the path forwardThe bulwark scan flags one Critical on this PR: What it is Why it can't be remediated in this PR right now
Exposure context Path forward
Recommendation: merge on the green |
There was a problem hiding this comment.
✅ CVE scan completed successfully.
Scan Summary:
- Total images scanned: 4
- Clean images: 2
- Images with CVEs: 2
- Total CVEs found: 8
🔴 Critical CVEs: 1
🟠 High CVEs: 0
🟡 Medium CVEs: 1
🟢 Low CVEs: 6
Images with CVEs:
- cgr.dev/chainguard/python:latest-dev: 7 CVEs (Critical: 1, High: 0, Medium: 1, Low: 5)
Critical CVEs: CVE-2026-7210 - cgr.dev/chainguard/redis:latest: 1 CVEs (Critical: 0, High: 0, Medium: 0, Low: 1)
nvidia-vss-data-infrastructure — VSS 3.x, pack
3.2.0VSS 3.x base data stores (redis, postgres, phoenix, elasticsearch, kibana) as a Helm chart, plus the cross-pack
hf-token-secretand thevss-platformConfigMap as kubeManifests (Palette resolves their.Values/spectro-var from themanifests.<name>values sub-tree). Note: kafka + logstash (search/alerts event streaming) are deferred — logstash needs a VSS-built image with the protobuf/redis-stream plugins (not the stocklogstash:9.3.0); they are not on the base summarization route.Versioning: chart/pack
version: 3.2.0(our packaging) ·appVersion: 3.1.0(upstream NVIDIA VSS Blueprint 3.x). Helm chart; images pinned invalues.yamlpack.content.images.Tested on NVIDIA GB10 / DGX Spark (arm64 SBSA)
Deployed via Palette add-on cluster profile
vss-dgx-spark-3xon edge clusteredge-gx10(single GB10). Full VSS 3.x route green — all 5 packs reportPack services are ready, cluster Running:Validation:
pack.jsonJSON-syntax/schema/version, logo, README, andpack.content.imagesall pass. Thecontent.imagespull (crane) fails for the gatednvcr.io/nim/*andnvcr.io/nvidia/vss-core/*images — the CI runner has no NGC credentials (the same image-pull exception as the 2.4 PRs #233–236; the cluster pulls them fine viangc-pull-secret).