feat: add Matrix appservice bot, platform-agnostic core, and Kubernetes deployment #1
@ -43,6 +43,7 @@ jobs:
|
||||
platforms: linux/amd64,linux/arm64
|
||||
tags: |
|
||||
git.aridgwayweb.com/armistace/steward:latest
|
||||
git.aridgwayweb.com/armistace/steward:${{ gitea.sha }}
|
||||
|
||||
- name: Deploy
|
||||
run: |
|
||||
@ -75,3 +76,4 @@ jobs:
|
||||
--from-literal=STEWARD__MATRIX__ALLOWED_USER_IDS=${{ vars.MATRIX_ALLOWED_USER_IDS }} \
|
||||
--namespace=steward
|
||||
kubectl apply -f kube/steward_deployment.yaml && kubectl apply -f kube/steward_service.yaml
|
||||
kubectl set image deployment/steward-deployment steward=git.aridgwayweb.com/armistace/steward:${{ gitea.sha }} --namespace=steward
|
||||
|
||||
@ -15,9 +15,19 @@ spec:
|
||||
labels:
|
||||
app: steward
|
||||
spec:
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
containers:
|
||||
- name: steward
|
||||
image: git.aridgwayweb.com/armistace/steward:latest
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
envFrom:
|
||||
- secretRef:
|
||||
name: steward-env
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user