Skip to content

Add security hardening examples - #27

Merged
RayLi-Muye merged 1 commit into
mainfrom
feature/security-hardening-examples
Jun 19, 2026
Merged

RayLi-Muye merged 1 commit into
mainfrom
feature/security-hardening-examples

Conversation

@RayLi-Muye

Copy link
Copy Markdown
Owner

Closes #5.

Scope

  • Adds an opt-in networkPolicy chart surface with defaults disabled.
  • Adds examples/values-security-hardening.yaml with placeholder IRSA, no generated Secret, and worker-only NetworkPolicy egress boundaries.
  • Adds docs/security.md for AWS permission, secret handling, and NetworkPolicy guidance.
  • Adds the security example to local render scripts, CI kubeconform validation, Makefile, and chart contract tests.
  • Updates README, architecture, development, evidence, and delivery docs.

Acceptance Criteria

  • Docs explain why AWS keys should not be committed or injected directly.
  • Example values show ServiceAccount annotation patterns using placeholders only.
  • NetworkPolicy example separates render workers from unrelated workloads.
  • Secret handling guidance avoids publishing renderer license files or customer credentials.

Validation

  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make test
  • make smoke-local
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make lint
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template >/tmp/renderfarm-template-aws.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-local >/tmp/renderfarm-template-local.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-minio >/tmp/renderfarm-template-minio.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-security >/tmp/renderfarm-template-security.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH scripts/render-examples.sh
  • python3 -m json.tool charts/render-worker/values.schema.json >/tmp/render-worker-values.schema.json
  • git diff --check
  • python3 /Users/winnie/.codex/skills/autoreview/scripts/autoreview --mode local

Docs Impact

Adds docs/security.md and links it from README. Updates architecture, development, evidence map, and delivery prompts to include the security example and NetworkPolicy validation path.

Risk And Rollback

Risk is low: networkPolicy.enabled defaults to false, so existing renders do not gain a NetworkPolicy unless users opt in. Roll back by reverting this PR if the NetworkPolicy values shape or public-safe example language needs revision.

Boundary

This PR does not deploy, release, publish packages, provision IAM roles, create Secrets Manager or External Secrets resources, create VPC endpoints/security groups/firewall rules, access credentials, use real AWS resources, or touch production data.

@RayLi-Muye
RayLi-Muye merged commit a20dc9d into main Jun 19, 2026
1 check passed
@RayLi-Muye
RayLi-Muye deleted the feature/security-hardening-examples branch June 19, 2026 01:50
@RayLi-Muye

Copy link
Copy Markdown
Owner Author

Post-merge validation summary:

Local validation before merge:

  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make test
  • make smoke-local
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make lint
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template >/tmp/renderfarm-template-aws.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-local >/tmp/renderfarm-template-local.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-minio >/tmp/renderfarm-template-minio.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH make template-security >/tmp/renderfarm-template-security.yaml
  • PATH=/tmp/codex-renderfarm-tools/bin:$PATH scripts/render-examples.sh
  • python3 -m json.tool charts/render-worker/values.schema.json >/tmp/render-worker-values.schema.json
  • git diff --check
  • python3 /Users/winnie/.codex/skills/autoreview/scripts/autoreview --mode local

Boundary: no deploy, release, package publish, real AWS resources, credential access, production data operation, or destructive git operation was performed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add security hardening examples for AWS permissions and secrets

1 participant