fix: k8s ingress rewrites all paths, add TLS, securityContext, resource limits, probes - #16
Merged
Merged
Conversation
…source limits, probes - Ingress: fixed rewrite-target from '/' to '/' with regex capture so /api/auth/login becomes /auth/login (not /) - Ingress: added TLS section with atlas-tls secret - Ingress: added ssl-redirect annotation, explicit ingressClassName - Deployments: added pod securityContext (runAsNonRoot, runAsUser, fsGroup) - Deployments: added container securityContext (no ptrace, no CAP) - Deployments: added resource requests/limits (cpu/memory) on all containers - Deployments: added livenessProbe and readinessProbe on all containers
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Kubernetes Ingress & Deployment Security Fix
Issues fixed
1. Ingress rewrite-target: / breaks all routes
ginx.ingress.kubernetes.io/rewrite-target: /\ stripped every path to just /\
2. No TLS configured
3. No securityContext on any deployment
unAsNonRoot: true,
unAsUser: 1001, \sGroup: 1001\
4. No resource limits
equests\ (100m cpu / 128Mi memory) and \limits\ (500m cpu / 256Mi memory) on all 14 containers
5. No liveness/readiness probes
eadinessProbe\ (httpGet /health) with appropriate delays on all containers
Files changed