Inactive
Notice ID:RFI_HNC_SonaType
Our goal is to identify a solution that can provide a repository manager that organizes, stores and distributes development artifacts in a DevSecOps environment. The repository should provide a single...
Our goal is to identify a solution that can provide a repository manager that organizes, stores and distributes development artifacts in a DevSecOps environment. The repository should provide a single point of reference for approved application containers and software artifacts for users. The repository will store, integrate with keycloak identity credential and access management (ICAM) and make available to operational organizations for evaluation and operational acceptance that have been through Continuous Integration (CI) and automated Continuous Deployment (CD) pipelines. Thereby, creating a DevSecOps compliant express lane for certification to field (CtF) and deployment of applications. The following are some of the key characteristics that we are using to meet our organizational objectives. While this list is not exhaustive, it does provide a snapshot of some of the most important requirements for our environment: Ability to store artifacts in AWS S3 Create Docker repository mirrors Available as a helm chart / containerized deployment for Kubernetes Supports SAML or OIDC authentication and authorization (Group assertions from the Idp are honored) Role-based access control management (RBAC) for local images Supports the creation and use of apt, docker, raw, maven2, rpm, pypi, npm, conda, go, gitlfs, helm, nuget, r, and yum repositories. Supports the use of api tokens / personal access tokens to retrieve software programmatically Supports the use of subdomain routing, and the use of multiple subdomains for assigning to repositories Support for multiple authentication systems Proxy access to external repositories Ability to record use in auditable logs so that activity can be traced to a single user Optimized for automation