fix: harden k8s security context and use SHA-tagged images

Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
  in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
  image to the SHA for idempotent rollbacks.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
Andrew Ridgway 2026-08-18 21:53:11 +10:00
parent 0a7273b321
commit 9c36b373d2
Signed by: armistace
GPG Key ID: C8D9EAC514B47EF1
2 changed files with 12 additions and 0 deletions

View File

@ -43,6 +43,7 @@ jobs:
platforms: linux/amd64,linux/arm64 platforms: linux/amd64,linux/arm64
tags: | tags: |
git.aridgwayweb.com/armistace/steward:latest git.aridgwayweb.com/armistace/steward:latest
git.aridgwayweb.com/armistace/steward:${{ gitea.sha }}
- name: Deploy - name: Deploy
run: | run: |
@ -75,3 +76,4 @@ jobs:
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \ --from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
--namespace=steward --namespace=steward
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward

View File

@ -15,9 +15,19 @@ spec:
labels: labels:
app: steward app: steward
spec: spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
containers: containers:
- name: steward - name: steward
image: git.aridgwayweb.com/armistace/steward:latest image: git.aridgwayweb.com/armistace/steward:latest
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
envFrom: envFrom:
- secretRef: - secretRef:
name: steward-env name: steward-env