From 9c36b373d26a59862b09cf199c8ae9be9953b81b Mon Sep 17 00:00:00 2001 From: Andrew Ridgway Date: Tue, 18 Aug 2026 21:53:11 +1000 Subject: [PATCH] fix: harden k8s security context and use SHA-tagged images Address pr_reviewer findings: - Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps in the deployment securityContext. - Tag images with the git SHA in addition to latest, and pin the deployed image to the SHA for idempotent rollbacks. Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus --- .gitea/workflows/build_push.yml | 2 ++ kube/steward_deployment.yaml | 10 ++++++++++ 2 files changed, 12 insertions(+) diff --git a/.gitea/workflows/build_push.yml b/.gitea/workflows/build_push.yml index 29e0ad7..0cc9911 100644 --- a/.gitea/workflows/build_push.yml +++ b/.gitea/workflows/build_push.yml @@ -43,6 +43,7 @@ jobs: platforms: linux/amd64,linux/arm64 tags: | git.aridgwayweb.com/armistace/steward:latest + git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} - name: Deploy run: | @@ -75,3 +76,4 @@ jobs: --from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \ --namespace=steward kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml + kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward diff --git a/kube/steward_deployment.yaml b/kube/steward_deployment.yaml index b475294..5e9a126 100644 --- a/kube/steward_deployment.yaml +++ b/kube/steward_deployment.yaml @@ -15,9 +15,19 @@ spec: labels: app: steward spec: + securityContext: + runAsNonRoot: true + runAsUser: 1000 + runAsGroup: 1000 + fsGroup: 1000 containers: - name: steward image: git.aridgwayweb.com/armistace/steward:latest + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL envFrom: - secretRef: name: steward-env