Skip to content

feat: experiment setting up infra for private vuln feeds#5536

Open
michaelkedar wants to merge 3 commits into
google:masterfrom
michaelkedar:private-osv🤫

Hidden character warning

The head ref may contain hidden characters: "private-osv\ud83e\udd2b"
Open

feat: experiment setting up infra for private vuln feeds#5536
michaelkedar wants to merge 3 commits into
google:masterfrom
michaelkedar:private-osv🤫

Conversation

@michaelkedar

@michaelkedar michaelkedar commented Jun 16, 2026

Copy link
Copy Markdown
Member

There's growing internal interest in being able to have internal vuln stores.
Set up some terraform configuration to be able to deploy another instance of the vuln pipeline without the website / API.

  • Duplicated much of the cluster/database/etc config into a new osv_pipeline module
    • eventually I will add move blocks and remove them from the core osv module to unify this.
  • As part of this, created a new service account for the cluster with restricted access (it should have everything it needs)
  • Added a new private-osv environment to deploy the infra to oss-vdb-test (for now). This isn't automatically deployed anywhere - I'll run terrform apply when this is ready to merge.

@michaelkedar michaelkedar marked this pull request as ready for review June 16, 2026 01:57
@michaelkedar michaelkedar requested a review from another-rex June 16, 2026 01:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant