fix: harden k8s security context and use SHA-tagged images
Address pr_reviewer findings: - Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps in the deployment securityContext. - Tag images with the git SHA in addition to latest, and pin the deployed image to the SHA for idempotent rollbacks. Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
parent
0a7273b321
commit
9c36b373d2
@ -43,6 +43,7 @@ jobs:
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: |
|
||||
git.aridgwayweb.com/armistace/steward:latest
|
||||
git.aridgwayweb.com/armistace/steward:${{ gitea.sha }}
|
||||
|
||||
- name: Deploy
|
||||
run: |
|
||||
@ -75,3 +76,4 @@ jobs:
|
||||
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
|
||||
--namespace=steward
|
||||
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
|
||||
kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward
|
||||
|
||||
@ -15,9 +15,19 @@ spec:
|
||||
labels:
|
||||
app: steward
|
||||
spec:
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
containers:
|
||||
- name: steward
|
||||
image: git.aridgwayweb.com/armistace/steward:latest
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: steward-env
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user