diff --git a/.tekton/scanner-db-build.yaml b/.tekton/scanner-db-build.yaml index 084c5fbdc..610104c14 100644 --- a/.tekton/scanner-db-build.yaml +++ b/.tekton/scanner-db-build.yaml @@ -61,6 +61,17 @@ spec: secret: secretName: '{{ git_auth_secret }}' + taskRunSpecs: + # The following are overrides to default step resources to prevent occasional or deterministic OOM kills. + - pipelineTaskName: rpms-signature-scan + stepSpecs: + - name: rpms-signature-scan + computeResources: + limits: + memory: 512Mi + requests: + memory: 512Mi + taskRunTemplate: serviceAccountName: build-pipeline-scanner-db diff --git a/.tekton/scanner-db-slim-build.yaml b/.tekton/scanner-db-slim-build.yaml index a75f8f36a..41db26b61 100644 --- a/.tekton/scanner-db-slim-build.yaml +++ b/.tekton/scanner-db-slim-build.yaml @@ -61,6 +61,17 @@ spec: secret: secretName: '{{ git_auth_secret }}' + taskRunSpecs: + # The following are overrides to default step resources to prevent occasional or deterministic OOM kills. + - pipelineTaskName: rpms-signature-scan + stepSpecs: + - name: rpms-signature-scan + computeResources: + limits: + memory: 512Mi + requests: + memory: 512Mi + taskRunTemplate: serviceAccountName: build-pipeline-scanner-db-slim