Fix Kubernetes manifest bugs, dedupe drifted files, harden security

- Rebuild manifests/doormile/miletruth.yaml (was corrupted since the
  initial commit - contained pasted AI/terminal output, truncated env
  var names/values, duplicate keys). Rebuilt from the confirmed-live
  config, secrets sourced via a Secret instead of plaintext values.
- Lock down the Kubernetes Dashboard: remove --enable-skip-login /
  --enable-insecure-login / --insecure-port=9090, remove the extra
  cluster-admin binding on the dashboard's own ServiceAccount, remove
  the now-dead insecure NodePort Service. Token-based login via the
  existing admin-user ServiceAccount is unaffected.
- Fix the duplicate `backendRefs` key under the same HTTPRoute rule in
  alaska.yaml (invalid/redundant YAML).
- Delete 6 redundant duplicate manifests (fiesta-sts/svc,
  atlantis-sts/svc, jupiter-sts/svc) that were partial, stale subsets
  of nearle-fiesta/atlantis/jupiter.yaml - one pair disagreed on the
  fiesta image tag entirely (v1.3.50 vs v1.3.67, neither of which
  matched what's actually live).
- Reconcile nearle-fiesta.yaml and nearle-jupiter.yaml image tags to
  the confirmed-live versions (v1.3.78 / v2.7.55).
- Add allowPrivilegeEscalation:false + drop-all-capabilities to
  fiesta/atlantis/jupiter/titan/ariane and the 5 specialized core
  workers, which previously ran with no securityContext at all.
- Add terminationGracePeriodSeconds:45 to the worker StatefulSets so
  Kubernetes gives the new graceful-shutdown drain (see worker.py
  changes) enough time before SIGKILL.
This commit is contained in:
Suriya
2026-07-18 16:07:32 +05:30
parent caac8413e9
commit 836c079a05
16 changed files with 117 additions and 373 deletions

View File

@@ -2,26 +2,31 @@ apiVersion: v1
kind: Namespace
metadata:
name: doormile
Read 1 file
Found the critical issue — INTERNAL_API_KEY not set in the manifest means
all /internal/* endpoode explicitly rejects empty keys). That plus the NATS_URL duplicate.
Here's the corrected miletruth.yaml with all missing env vars added. Run
this on the server:
cat > /root/kuberneteh.yaml << 'EOF'
labels:
name: doormile
---
apiVersion: v1
kind: Namespace
kind: Secret
metadata:
name: doormile
name: doormile-secrets
namespace: doormile
labels:
app: doormile
type: Opaque
stringData:
DB_PASSWORD: "Package@321#"
REDIS_PASSWORD: "Package@321#"
NATS_USER: "doormile"
NATS_PASSWORD: "Package@321#"
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: doormile
namespace: doormile
labels:
app: doormile
app-group: doormile-api
spec:
serviceName: "doormile-service"
replicas: 3
@@ -33,57 +38,68 @@ spec:
metadata:
labels:
app: doormile
app-group: do
app-group: doormile-api
spec:
containers:
- name: doormile
image: doormi
image: doormile/doormile-backend:latest
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 8081
env:
- name: ENV
value: "production"
- name: APP_PORT
value: "8081"
- name: DB_HO
- name: DB_HOST
value: "31.97.228.132"
- name: DB_PO
- name: DB_PORT
value: "5433"
- name: DB_NA
- name: DB_NAME
value: "logistics"
- name: DB_US
- name: DB_USER
value: "admin"
- name: DB_PASSWORD
value: "Pac
valueFrom:
secretKeyRef:
name: doormile-secrets
key: DB_PASSWORD
- name: REDIS_HOST
value: "31.97.228.132"
- name: REDIS
- name: REDIS_PORT
value: "6379"
- name: REDIS_USER
value: "adm
- name: REDIS_PASSWORD
value: "Package@321#"
- name: JWT_S
value: "DoormileSuperSecretJWTKey2026!"
- name: NATS_
valueFrom:
secretKeyRef:
name: doormile-secrets
key: REDIS_PASSWORD
- name: NATS_URL
value: "nats://66.116.226.161:4223"
- name: NATS_
value: "doormile"
- name: NATS_USER
valueFrom:
secretKeyRef:
name: doormile-secrets
key: NATS_USER
- name: NATS_PASSWORD
value: "Pac
- name: INTERNAL_API_KEY
value: "doormile-internal-2024"
valueFrom:
secretKeyRef:
name: doormile-secrets
key: NATS_PASSWORD
---
apiVersion: v1
kind: Service
metadata:
name: doormile-service
namespace: doormile
labels:
app: doormile
spec:
type: NodePort
selector:
app-group: doormile-api
ports:
- protocol: TCP
port: 8081
targetPort: 808
nodePort: 30830
port: 8081 # Expose port 8081 internally
targetPort: 8081 # The port the backend application actually listens on
nodePort: 30830 # This must match what NGINX is looking for