steward_mirror/kube/steward_deployment.yaml
Andrew Ridgway 9c36b373d2
fix: harden k8s security context and use SHA-tagged images
Address pr_reviewer findings:
- Enforce non-root (UID/GID 1000), no privilege escalation, drop all caps
  in the deployment securityContext.
- Tag images with the git SHA in addition to latest, and pin the deployed
  image to the SHA for idempotent rollbacks.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-08-18 21:53:11 +10:00

66 lines
1.3 KiB
YAML

apiVersion: apps/v1
kind: Deployment
metadata:
name: steward-deployment
labels:
app: steward
namespace: steward
spec:
replicas: 1
selector:
matchLabels:
app: steward
template:
metadata:
labels:
app: steward
spec:
securityContext:
runAsNonRoot: true
runAsUser: 1000
runAsGroup: 1000
fsGroup: 1000
containers:
- name: steward
image: git.aridgwayweb.com/armistace/steward:latest
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
envFrom:
- secretRef:
name: steward-env
env:
- name: THREAD_MEMORY_PATH
value: /data/thread_memory.json
volumeMounts:
- name: steward-data
mountPath: /data
resources:
requests:
memory: "256Mi"
cpu: "100m"
limits:
memory: "1Gi"
cpu: "500m"
volumes:
- name: steward-data
persistentVolumeClaim:
claimName: steward-storage
imagePullSecrets:
- name: regcred
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: steward-storage
namespace: steward
spec:
accessModes:
- ReadWriteOnce
storageClassName: longhorn
resources:
requests:
storage: 1Gi