Fix Kubernetes manifest bugs, dedupe drifted files, harden security

- Rebuild manifests/doormile/miletruth.yaml (was corrupted since the
  initial commit - contained pasted AI/terminal output, truncated env
  var names/values, duplicate keys). Rebuilt from the confirmed-live
  config, secrets sourced via a Secret instead of plaintext values.
- Lock down the Kubernetes Dashboard: remove --enable-skip-login /
  --enable-insecure-login / --insecure-port=9090, remove the extra
  cluster-admin binding on the dashboard's own ServiceAccount, remove
  the now-dead insecure NodePort Service. Token-based login via the
  existing admin-user ServiceAccount is unaffected.
- Fix the duplicate `backendRefs` key under the same HTTPRoute rule in
  alaska.yaml (invalid/redundant YAML).
- Delete 6 redundant duplicate manifests (fiesta-sts/svc,
  atlantis-sts/svc, jupiter-sts/svc) that were partial, stale subsets
  of nearle-fiesta/atlantis/jupiter.yaml - one pair disagreed on the
  fiesta image tag entirely (v1.3.50 vs v1.3.67, neither of which
  matched what's actually live).
- Reconcile nearle-fiesta.yaml and nearle-jupiter.yaml image tags to
  the confirmed-live versions (v1.3.78 / v2.7.55).
- Add allowPrivilegeEscalation:false + drop-all-capabilities to
  fiesta/atlantis/jupiter/titan/ariane and the 5 specialized core
  workers, which previously ran with no securityContext at all.
- Add terminationGracePeriodSeconds:45 to the worker StatefulSets so
  Kubernetes gives the new graceful-shutdown drain (see worker.py
  changes) enough time before SIGKILL.
This commit is contained in:
Suriya
2026-07-18 16:07:32 +05:30
parent caac8413e9
commit 836c079a05
16 changed files with 117 additions and 373 deletions

View File

@@ -330,10 +330,6 @@ spec:
- name: deliveries-service
port: 8000
weight: 100
backendRefs:
- name: deliveries-service
port: 8000
weight: 100
- matches:
- path:
type: PathPrefix

View File

@@ -34,19 +34,6 @@ metadata:
kubernetes.io/service-account.name: "admin-user"
type: kubernetes.io/service-account-token
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: kubernetes-dashboard-admin
roleRef:
apiGroup: rbac.authorization.k8s.io
kind: ClusterRole
name: cluster-admin
subjects:
- kind: ServiceAccount
name: kubernetes-dashboard
namespace: kubernetes-dashboard
---
apiVersion: apps/v1
kind: Deployment
metadata:
@@ -75,9 +62,6 @@ spec:
args:
- --auto-generate-certificates
- --namespace=kubernetes-dashboard
- --enable-skip-login
- --enable-insecure-login
- --insecure-port=9090
volumeMounts:
- name: kubernetes-dashboard-certs
mountPath: /certs
@@ -135,10 +119,6 @@ spec:
targetPort: 8443
protocol: TCP
name: https
- port: 9090
targetPort: 9090
protocol: TCP
name: http
selector:
k8s-app: kubernetes-dashboard
---
@@ -307,22 +287,3 @@ spec:
targetPort: 8083
nodePort: 30826
protocol: TCP
---
apiVersion: v1
kind: Service
metadata:
name: dashboard-loadbalancer
namespace: kubernetes-dashboard
labels:
app.kubernetes.io/name: kubernetes-dashboard
app.kubernetes.io/component: loadbalancer
spec:
type: NodePort
selector:
k8s-app: kubernetes-dashboard
ports:
- name: http
port: 9090
targetPort: 9090 # Dashboard HTTP port
nodePort: 30827 # Fixed NodePort for nginx proxy
protocol: TCP

View File

@@ -27,6 +27,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
securityContext:
runAsUser: 1000
runAsGroup: 1000

View File

@@ -22,6 +22,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
tolerations:
- key: dedicated
operator: Equal
@@ -58,6 +59,11 @@ spec:
- name: worker
image: workolik360/nats-worker:v1.1.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
command: ["python3", "-u", "/scripts/worker.py"]
volumeMounts:
- name: worker-script-vol
@@ -132,6 +138,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
tolerations:
- key: dedicated
operator: Equal
@@ -168,6 +175,11 @@ spec:
- name: worker
image: workolik360/nats-worker:v1.1.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
command: ["python3", "-u", "/scripts/worker.py"]
volumeMounts:
- name: worker-script-vol
@@ -236,6 +248,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
tolerations:
- key: dedicated
operator: Equal
@@ -272,6 +285,11 @@ spec:
- name: worker
image: workolik360/nats-worker:v1.1.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
command: ["python3", "-u", "/scripts/worker.py"]
volumeMounts:
- name: worker-script-vol
@@ -346,6 +364,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
tolerations:
- key: dedicated
operator: Equal
@@ -382,6 +401,11 @@ spec:
- name: worker
image: workolik360/nats-worker:v1.1.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
command: ["python3", "-u", "/scripts/worker.py"]
volumeMounts:
- name: worker-script-vol
@@ -456,6 +480,7 @@ spec:
prometheus.io/port: "9090"
prometheus.io/path: "/metrics"
spec:
terminationGracePeriodSeconds: 45
tolerations:
- key: dedicated
operator: Equal
@@ -492,6 +517,11 @@ spec:
- name: worker
image: workolik360/nats-worker:v1.1.0
imagePullPolicy: IfNotPresent
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
command: ["python3", "-u", "/scripts/worker.py"]
volumeMounts:
- name: worker-script-vol

View File

@@ -2,26 +2,31 @@ apiVersion: v1
kind: Namespace
metadata:
name: doormile
Read 1 file
Found the critical issue — INTERNAL_API_KEY not set in the manifest means
all /internal/* endpoode explicitly rejects empty keys). That plus the NATS_URL duplicate.
Here's the corrected miletruth.yaml with all missing env vars added. Run
this on the server:
cat > /root/kuberneteh.yaml << 'EOF'
apiVersion: v1
kind: Namespace
metadata:
labels:
name: doormile
---
apiVersion: v1
kind: Secret
metadata:
name: doormile-secrets
namespace: doormile
labels:
app: doormile
type: Opaque
stringData:
DB_PASSWORD: "Package@321#"
REDIS_PASSWORD: "Package@321#"
NATS_USER: "doormile"
NATS_PASSWORD: "Package@321#"
---
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: doormile
namespace: doormile
labels:
app: doormile
app-group: doormile-api
spec:
serviceName: "doormile-service"
replicas: 3
@@ -33,57 +38,68 @@ spec:
metadata:
labels:
app: doormile
app-group: do
app-group: doormile-api
spec:
containers:
- name: doormile
image: doormi
image: doormile/doormile-backend:latest
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 8081
env:
- name: ENV
value: "production"
- name: APP_PORT
value: "8081"
- name: DB_HO
- name: DB_HOST
value: "31.97.228.132"
- name: DB_PO
- name: DB_PORT
value: "5433"
- name: DB_NA
- name: DB_NAME
value: "logistics"
- name: DB_US
- name: DB_USER
value: "admin"
- name: DB_PASSWORD
value: "Pac
valueFrom:
secretKeyRef:
name: doormile-secrets
key: DB_PASSWORD
- name: REDIS_HOST
value: "31.97.228.132"
- name: REDIS
- name: REDIS_PORT
value: "6379"
- name: REDIS_USER
value: "adm
- name: REDIS_PASSWORD
value: "Package@321#"
- name: JWT_S
value: "DoormileSuperSecretJWTKey2026!"
- name: NATS_
valueFrom:
secretKeyRef:
name: doormile-secrets
key: REDIS_PASSWORD
- name: NATS_URL
value: "nats://66.116.226.161:4223"
- name: NATS_
value: "doormile"
- name: NATS_USER
valueFrom:
secretKeyRef:
name: doormile-secrets
key: NATS_USER
- name: NATS_PASSWORD
value: "Pac
- name: INTERNAL_API_KEY
value: "doormile-internal-2024"
valueFrom:
secretKeyRef:
name: doormile-secrets
key: NATS_PASSWORD
---
apiVersion: v1
kind: Service
metadata:
name: doormile-service
namespace: doormile
labels:
app: doormile
spec:
type: NodePort
selector:
app-group: doormile-api
ports:
- protocol: TCP
port: 8081
targetPort: 808
nodePort: 30830
port: 8081 # Expose port 8081 internally
targetPort: 8081 # The port the backend application actually listens on
nodePort: 30830 # This must match what NGINX is looking for

View File

@@ -1,61 +0,0 @@
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: atlantis
namespace: nearle
labels:
app: atlantis
spec:
serviceName: "atlantis"
replicas: 2
selector:
matchLabels:
app: atlantis
template:
metadata:
labels:
app: atlantis
spec:
tolerations:
- key: dedicated
operator: Equal
value: apps
effect: NoSchedule
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-role.workolik/app
operator: In
values:
- "true"
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app: atlantis
topologyKey: kubernetes.io/hostname
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app: atlantis
containers:
- name: backend
image: nearlecommerce/atlantis:v0.0.41
imagePullPolicy: Always
ports:
- containerPort: 3000
env:
- name: PORT
value: "3000"
envFrom:
- configMapRef:
name: nearle-config
- secretRef:
name: app-secrets

View File

@@ -1,16 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: atlantis
namespace: nearle
labels:
app: atlantis
spec:
type: NodePort
ports:
- port: 80
targetPort: 3000
nodePort: 30825
protocol: TCP
selector:
app: atlantis

View File

@@ -1,99 +0,0 @@
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: fiesta
namespace: nearle
labels:
app: fiesta
spec:
serviceName: "fiesta"
replicas: 3
selector:
matchLabels:
app: fiesta
template:
metadata:
labels:
app: fiesta
spec:
tolerations:
- key: dedicated
operator: Equal
value: apps
effect: NoSchedule
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-role.workolik/app
operator: In
values:
- "true"
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app: fiesta
topologyKey: kubernetes.io/hostname
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app: fiesta
containers:
- name: backend
image: nearlecommerce/fiesta:v1.3.67
imagePullPolicy: Always
ports:
- containerPort: 1122
envFrom:
- configMapRef:
name: nearle-config
- secretRef:
name: app-secrets
env:
- name: PORT
value: "1122"
- name: NATS_USER
valueFrom:
secretKeyRef:
name: nats-credentials
key: username
- name: NATS_PASSWORD
valueFrom:
secretKeyRef:
name: nats-credentials
key: password
- name: gateway
image: workolik360/alaska:v1.2.0
imagePullPolicy: Always
ports:
- containerPort: 8000
name: http
volumeMounts:
- name: gateway-script
mountPath: /app/app.py
subPath: app.py
envFrom:
- configMapRef:
name: nearle-config
env:
- name: NATS_USER
valueFrom:
secretKeyRef:
name: nats-credentials
key: username
- name: NATS_PASSWORD
valueFrom:
secretKeyRef:
name: nats-credentials
key: password
volumes:
- name: gateway-script
configMap:
name: fiesta-gateway-script

View File

@@ -1,21 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: fiesta
namespace: nearle
labels:
app: fiesta
spec:
type: NodePort
ports:
- port: 80
targetPort: 1122
nodePort: 30823
protocol: TCP
name: main
- port: 8000
targetPort: 8000
name: gateway
protocol: TCP
selector:
app: fiesta

View File

@@ -1,77 +0,0 @@
apiVersion: apps/v1
kind: StatefulSet
metadata:
name: jupiter
namespace: nearle
labels:
app: jupiter
spec:
serviceName: "jupiter"
replicas: 3
selector:
matchLabels:
app: jupiter
template:
metadata:
labels:
app: jupiter
spec:
tolerations:
- key: dedicated
operator: Equal
value: apps
effect: NoSchedule
affinity:
nodeAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
nodeSelectorTerms:
- matchExpressions:
- key: node-role.workolik/app
operator: In
values:
- "true"
podAntiAffinity:
preferredDuringSchedulingIgnoredDuringExecution:
- weight: 100
podAffinityTerm:
labelSelector:
matchLabels:
app: jupiter
topologyKey: kubernetes.io/hostname
topologySpreadConstraints:
- maxSkew: 1
topologyKey: kubernetes.io/hostname
whenUnsatisfiable: ScheduleAnyway
labelSelector:
matchLabels:
app: jupiter
containers:
- name: jupiter
image: nearlecommerce/jupiter:v2.7.53
imagePullPolicy: Always
ports:
- containerPort: 1009
env:
- name: PORT
value: "1009"
- name: TZ
value: "Asia/Kolkata"
volumeMounts:
- name: tz-config
mountPath: /etc/localtime
readOnly: true
- name: tz-data
mountPath: /usr/share/zoneinfo
readOnly: true
envFrom:
- configMapRef:
name: nearle-config
- secretRef:
name: app-secrets
volumes:
- name: tz-config
hostPath:
path: /usr/share/zoneinfo/Asia/Kolkata
- name: tz-data
hostPath:
path: /usr/share/zoneinfo

View File

@@ -1,16 +0,0 @@
apiVersion: v1
kind: Service
metadata:
name: jupiter
namespace: nearle
labels:
app: jupiter
spec:
type: NodePort
ports:
- port: 80
targetPort: 1009
nodePort: 30822
protocol: TCP
selector:
app: jupiter

View File

@@ -49,6 +49,11 @@ spec:
- name: backend
image: nearlecommerce/ariane:v1.0.22
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 1000
env:

View File

@@ -49,6 +49,11 @@ spec:
- name: backend
image: nearlecommerce/atlantis:v0.0.41
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 3000
env:

View File

@@ -47,8 +47,13 @@ spec:
app: fiesta
containers:
- name: backend
image: nearlecommerce/fiesta:v1.3.50
image: nearlecommerce/fiesta:v1.3.78
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 1122
envFrom:
@@ -72,6 +77,11 @@ spec:
- name: gateway
image: workolik360/alaska:v1.2.0
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 8000
name: http

View File

@@ -47,8 +47,13 @@ spec:
app: jupiter
containers:
- name: jupiter
image: nearlecommerce/jupiter:v2.7.31
image: nearlecommerce/jupiter:v2.7.55
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 1009
env:

View File

@@ -49,6 +49,11 @@ spec:
- name: backend
image: groomgear/groomgear:v1.0.41
imagePullPolicy: Always
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
ports:
- containerPort: 1006
---