Repository navigation
Add security hardening examples - #27
Merged
Merged
Conversation
Owner
Author
|
Post-merge validation summary:
Local validation before merge:
Boundary: no deploy, release, package publish, real AWS resources, credential access, production data operation, or destructive git operation was performed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #5.
Scope
networkPolicychart surface with defaults disabled.examples/values-security-hardening.yamlwith placeholder IRSA, no generated Secret, and worker-only NetworkPolicy egress boundaries.docs/security.mdfor AWS permission, secret handling, and NetworkPolicy guidance.Acceptance Criteria
Validation
PATH=/tmp/codex-renderfarm-tools/bin:$PATH make testmake smoke-localPATH=/tmp/codex-renderfarm-tools/bin:$PATH make lintPATH=/tmp/codex-renderfarm-tools/bin:$PATH make template >/tmp/renderfarm-template-aws.yamlPATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-local >/tmp/renderfarm-template-local.yamlPATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-minio >/tmp/renderfarm-template-minio.yamlPATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-security >/tmp/renderfarm-template-security.yamlPATH=/tmp/codex-renderfarm-tools/bin:$PATH scripts/render-examples.shpython3 -m json.tool charts/render-worker/values.schema.json >/tmp/render-worker-values.schema.jsongit diff --checkpython3 /Users/winnie/.codex/skills/autoreview/scripts/autoreview --mode localDocs Impact
Adds
docs/security.mdand links it from README. Updates architecture, development, evidence map, and delivery prompts to include the security example and NetworkPolicy validation path.Risk And Rollback
Risk is low:
networkPolicy.enableddefaults tofalse, so existing renders do not gain a NetworkPolicy unless users opt in. Roll back by reverting this PR if the NetworkPolicy values shape or public-safe example language needs revision.Boundary
This PR does not deploy, release, publish packages, provision IAM roles, create Secrets Manager or External Secrets resources, create VPC endpoints/security groups/firewall rules, access credentials, use real AWS resources, or touch production data.