Skip to content

BB-Common Library Chart

Version: 1.5.0 Type: application Maintenance Track: bb_integrated

A Helm library chart providing standardized Kubernetes resource templates for Platform One Big Bang packages.

Overview

BB-Common is a library chart designed to reduce code duplication and accelerate package development within the Platform One Big Bang ecosystem. Big Bang is the Department of Defense’s declarative continuous delivery tool for deploying DoD-hardened and approved packages into Kubernetes clusters.

This chart provides reusable templates and abstractions for common Kubernetes resources, starting with a sophisticated network policy framework that simplifies security configuration while maintaining compliance with DoD DevSecOps requirements.

Features

Network Policies

The centerpiece of bb-common is its comprehensive network policy system that transforms complex Kubernetes NetworkPolicy resources into intuitive, declarative configurations:

  • Shorthand Syntax: Express complex network rules with simple notation like backend/api:8080 or 10.0.0.0/8:443
  • Security by Default: Automatic deny-all policies with selective allow rules following zero-trust principles
  • Built-in Definitions: Pre-configured rules for common patterns (Istio gateway, monitoring, DNS)
  • Smart Defaults: Automatically handles DNS resolution, in-namespace communication, and Istio control plane traffic
  • Full Flexibility: Support for raw NetworkPolicy specs when needed

Learn more about network policies →

Istio Resources

BB-Common provides templates for Istio service mesh resources including authorization policies, peer authentication, and ambient waypoint Gateways.

  • Authorization Policies: Generate Istio AuthorizationPolicies automatically from NetworkPolicy configurations or define custom policies
  • Secure Default Policies: Default Sidecar, PeerAuthentication, AuthorizationPolicy configuration for enhanced security posture
  • Ambient Waypoints: Render Gateway API waypoint resources for ambient L7 policy, routing, and telemetry use cases

Learn more about Istio resources →

Routes

Simplified configuration for Istio VirtualServices and traffic routing:

  • Gateway Integration: Easy configuration of ingress routes through Istio gateways
  • Traffic Management: Declare routing rules with minimal boilerplate

Note: Routes require Istio CRDs (networking.istio.io/v1) to be available in the cluster. Routes are conditionally rendered only when Istio CRDs are available.

Learn more about routes →

Installation

As a Subchart

Add bb-common to your chart dependencies:

# Chart.yaml
dependencies:
  - name: bb-common
    version: "<version>"
    repository: oci://registry1.dso.mil/bigbang

Then configure in your values:

# values.yaml
bb-common:
  networkPolicies:
    enabled: true
    egress:
      from:
        my-app:
          to:
            k8s:
              backend/api:8080: true

As a Library Chart

[!NOTE] This method is deprecated and will no longer be available in the near future

For more control, use bb-common as a library:

# Chart.yaml
dependencies:
  - name: bb-common
    version: "<version>"
    repository: oci://registry1.dso.mil/bigbang

Include templates in your chart:

# templates/bigbang/network-policies.yaml
{{- include "bb-common.network-policies.render" . }}
# templates/bigbang/istio.yaml
{{- include "bb-common.istio.render" . }}
# templates/bigbang/routes.yaml
{{- include "bb-common.routes.render" . }}

Configure directly in values:

# values.yaml
networkPolicies:
  enabled: true
  egress:
    from:
      my-app:
        to:
          k8s:
            backend/api:8080: true

Development

Prerequisites

Running Tests

cd chart
helm dep update
helm unittest .

Testing Template Generation

Preview generated resources:

cd chart
helm template my-release . --values values.yaml

Contributing

Please see CONTRIBUTING.md for contribution guidelines.

Roadmap

The goal is to provide a comprehensive library that standardizes Big Bang integration while reducing boilerplate across all packages.

Future additions to bb-common will include: - Service Entries: External service registration

License

See https://repo1.dso.mil/big-bang/product/packages/bb-common/-/tree/main/LICENSE for licensing information.

Support

For issues, feature requests, or questions: