fix: harden k8s security context and use SHA-tagged images
Address pr_reviewer findings: - Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps in the deployment securityContext. - Tag images with the git SHA in addition to latest, and pin the deployed image to the SHA for idempotent rollbacks. Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
parent
0a7273b321
commit
9c36b373d2
@ -43,6 +43,7 @@ jobs:
|
|||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
tags: |
|
tags: |
|
||||||
git.aridgwayweb.com/armistace/steward:latest
|
git.aridgwayweb.com/armistace/steward:latest
|
||||||
|
git.aridgwayweb.com/armistace/steward:${{ gitea.sha }}
|
||||||
|
|
||||||
- name: Deploy
|
- name: Deploy
|
||||||
run: |
|
run: |
|
||||||
@ -75,3 +76,4 @@ jobs:
|
|||||||
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
|
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
|
||||||
--namespace=steward
|
--namespace=steward
|
||||||
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
|
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
|
||||||
|
kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward
|
||||||
|
|||||||
@ -15,9 +15,19 @@ spec:
|
|||||||
labels:
|
labels:
|
||||||
app: steward
|
app: steward
|
||||||
spec:
|
spec:
|
||||||
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
runAsGroup: 1000
|
||||||
|
fsGroup: 1000
|
||||||
containers:
|
containers:
|
||||||
- name: steward
|
- name: steward
|
||||||
image: git.aridgwayweb.com/armistace/steward:latest
|
image: git.aridgwayweb.com/armistace/steward:latest
|
||||||
|
securityContext:
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
envFrom:
|
envFrom:
|
||||||
- secretRef:
|
- secretRef:
|
||||||
name: steward-env
|
name: steward-env
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user