2 Commits

Author SHA1 Message Date
9c36b373d2
fix: harden k8s security context and use SHA-tagged images
Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
  in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
  image to the SHA for idempotent rollbacks.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-08-18 21:53:11 +10:00
260720dd10
chore: add Kubernetes deployment manifests and Gitea Actions build workflow
Mirror the pr_reviewer deployment pattern: Gitea Actions builds a multi-arch
image in the gitea-runner namespace, pushes to git.aridgwayweb.com, recreates
the steward namespace with regcred + env secret, and applies kube manifests.
Add .omo/ to .gitignore.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-08-18 21:37:53 +10:00