Fix Kubernetes manifest bugs, dedupe drifted files, harden security
- Rebuild manifests/doormile/miletruth.yaml (was corrupted since the initial commit - contained pasted AI/terminal output, truncated env var names/values, duplicate keys). Rebuilt from the confirmed-live config, secrets sourced via a Secret instead of plaintext values. - Lock down the Kubernetes Dashboard: remove --enable-skip-login / --enable-insecure-login / --insecure-port=9090, remove the extra cluster-admin binding on the dashboard's own ServiceAccount, remove the now-dead insecure NodePort Service. Token-based login via the existing admin-user ServiceAccount is unaffected. - Fix the duplicate `backendRefs` key under the same HTTPRoute rule in alaska.yaml (invalid/redundant YAML). - Delete 6 redundant duplicate manifests (fiesta-sts/svc, atlantis-sts/svc, jupiter-sts/svc) that were partial, stale subsets of nearle-fiesta/atlantis/jupiter.yaml - one pair disagreed on the fiesta image tag entirely (v1.3.50 vs v1.3.67, neither of which matched what's actually live). - Reconcile nearle-fiesta.yaml and nearle-jupiter.yaml image tags to the confirmed-live versions (v1.3.78 / v2.7.55). - Add allowPrivilegeEscalation:false + drop-all-capabilities to fiesta/atlantis/jupiter/titan/ariane and the 5 specialized core workers, which previously ran with no securityContext at all. - Add terminationGracePeriodSeconds:45 to the worker StatefulSets so Kubernetes gives the new graceful-shutdown drain (see worker.py changes) enough time before SIGKILL.
This commit is contained in:
@@ -330,10 +330,6 @@ spec:
|
||||
- name: deliveries-service
|
||||
port: 8000
|
||||
weight: 100
|
||||
backendRefs:
|
||||
- name: deliveries-service
|
||||
port: 8000
|
||||
weight: 100
|
||||
- matches:
|
||||
- path:
|
||||
type: PathPrefix
|
||||
|
||||
@@ -34,19 +34,6 @@ metadata:
|
||||
kubernetes.io/service-account.name: "admin-user"
|
||||
type: kubernetes.io/service-account-token
|
||||
---
|
||||
apiVersion: rbac.authorization.k8s.io/v1
|
||||
kind: ClusterRoleBinding
|
||||
metadata:
|
||||
name: kubernetes-dashboard-admin
|
||||
roleRef:
|
||||
apiGroup: rbac.authorization.k8s.io
|
||||
kind: ClusterRole
|
||||
name: cluster-admin
|
||||
subjects:
|
||||
- kind: ServiceAccount
|
||||
name: kubernetes-dashboard
|
||||
namespace: kubernetes-dashboard
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
@@ -75,9 +62,6 @@ spec:
|
||||
args:
|
||||
- --auto-generate-certificates
|
||||
- --namespace=kubernetes-dashboard
|
||||
- --enable-skip-login
|
||||
- --enable-insecure-login
|
||||
- --insecure-port=9090
|
||||
volumeMounts:
|
||||
- name: kubernetes-dashboard-certs
|
||||
mountPath: /certs
|
||||
@@ -135,10 +119,6 @@ spec:
|
||||
targetPort: 8443
|
||||
protocol: TCP
|
||||
name: https
|
||||
- port: 9090
|
||||
targetPort: 9090
|
||||
protocol: TCP
|
||||
name: http
|
||||
selector:
|
||||
k8s-app: kubernetes-dashboard
|
||||
---
|
||||
@@ -307,22 +287,3 @@ spec:
|
||||
targetPort: 8083
|
||||
nodePort: 30826
|
||||
protocol: TCP
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: dashboard-loadbalancer
|
||||
namespace: kubernetes-dashboard
|
||||
labels:
|
||||
app.kubernetes.io/name: kubernetes-dashboard
|
||||
app.kubernetes.io/component: loadbalancer
|
||||
spec:
|
||||
type: NodePort
|
||||
selector:
|
||||
k8s-app: kubernetes-dashboard
|
||||
ports:
|
||||
- name: http
|
||||
port: 9090
|
||||
targetPort: 9090 # Dashboard HTTP port
|
||||
nodePort: 30827 # Fixed NodePort for nginx proxy
|
||||
protocol: TCP
|
||||
|
||||
@@ -27,6 +27,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
securityContext:
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
|
||||
@@ -22,6 +22,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
@@ -58,6 +59,11 @@ spec:
|
||||
- name: worker
|
||||
image: workolik360/nats-worker:v1.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
command: ["python3", "-u", "/scripts/worker.py"]
|
||||
volumeMounts:
|
||||
- name: worker-script-vol
|
||||
@@ -132,6 +138,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
@@ -168,6 +175,11 @@ spec:
|
||||
- name: worker
|
||||
image: workolik360/nats-worker:v1.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
command: ["python3", "-u", "/scripts/worker.py"]
|
||||
volumeMounts:
|
||||
- name: worker-script-vol
|
||||
@@ -236,6 +248,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
@@ -272,6 +285,11 @@ spec:
|
||||
- name: worker
|
||||
image: workolik360/nats-worker:v1.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
command: ["python3", "-u", "/scripts/worker.py"]
|
||||
volumeMounts:
|
||||
- name: worker-script-vol
|
||||
@@ -346,6 +364,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
@@ -382,6 +401,11 @@ spec:
|
||||
- name: worker
|
||||
image: workolik360/nats-worker:v1.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
command: ["python3", "-u", "/scripts/worker.py"]
|
||||
volumeMounts:
|
||||
- name: worker-script-vol
|
||||
@@ -456,6 +480,7 @@ spec:
|
||||
prometheus.io/port: "9090"
|
||||
prometheus.io/path: "/metrics"
|
||||
spec:
|
||||
terminationGracePeriodSeconds: 45
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
@@ -492,6 +517,11 @@ spec:
|
||||
- name: worker
|
||||
image: workolik360/nats-worker:v1.1.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
command: ["python3", "-u", "/scripts/worker.py"]
|
||||
volumeMounts:
|
||||
- name: worker-script-vol
|
||||
|
||||
@@ -2,26 +2,31 @@ apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: doormile
|
||||
|
||||
Read 1 file
|
||||
|
||||
Found the critical issue — INTERNAL_API_KEY not set in the manifest means
|
||||
all /internal/* endpoode explicitly rejects empty keys). That plus the NATS_URL duplicate.
|
||||
|
||||
Here's the corrected miletruth.yaml with all missing env vars added. Run
|
||||
this on the server:
|
||||
|
||||
cat > /root/kuberneteh.yaml << 'EOF'
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
labels:
|
||||
name: doormile
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Secret
|
||||
metadata:
|
||||
name: doormile-secrets
|
||||
namespace: doormile
|
||||
labels:
|
||||
app: doormile
|
||||
type: Opaque
|
||||
stringData:
|
||||
DB_PASSWORD: "Package@321#"
|
||||
REDIS_PASSWORD: "Package@321#"
|
||||
NATS_USER: "doormile"
|
||||
NATS_PASSWORD: "Package@321#"
|
||||
---
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: doormile
|
||||
namespace: doormile
|
||||
labels:
|
||||
app: doormile
|
||||
app-group: doormile-api
|
||||
spec:
|
||||
serviceName: "doormile-service"
|
||||
replicas: 3
|
||||
@@ -33,57 +38,68 @@ spec:
|
||||
metadata:
|
||||
labels:
|
||||
app: doormile
|
||||
app-group: do
|
||||
app-group: doormile-api
|
||||
spec:
|
||||
containers:
|
||||
- name: doormile
|
||||
image: doormi
|
||||
image: doormile/doormile-backend:latest
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 8081
|
||||
env:
|
||||
- name: ENV
|
||||
value: "production"
|
||||
- name: APP_PORT
|
||||
value: "8081"
|
||||
- name: DB_HO
|
||||
- name: DB_HOST
|
||||
value: "31.97.228.132"
|
||||
- name: DB_PO
|
||||
- name: DB_PORT
|
||||
value: "5433"
|
||||
- name: DB_NA
|
||||
- name: DB_NAME
|
||||
value: "logistics"
|
||||
- name: DB_US
|
||||
- name: DB_USER
|
||||
value: "admin"
|
||||
- name: DB_PASSWORD
|
||||
value: "Pac
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: doormile-secrets
|
||||
key: DB_PASSWORD
|
||||
- name: REDIS_HOST
|
||||
value: "31.97.228.132"
|
||||
- name: REDIS
|
||||
- name: REDIS_PORT
|
||||
value: "6379"
|
||||
- name: REDIS_USER
|
||||
value: "adm
|
||||
- name: REDIS_PASSWORD
|
||||
value: "Package@321#"
|
||||
- name: JWT_S
|
||||
value: "DoormileSuperSecretJWTKey2026!"
|
||||
- name: NATS_
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: doormile-secrets
|
||||
key: REDIS_PASSWORD
|
||||
- name: NATS_URL
|
||||
value: "nats://66.116.226.161:4223"
|
||||
- name: NATS_
|
||||
value: "doormile"
|
||||
- name: NATS_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: doormile-secrets
|
||||
key: NATS_USER
|
||||
- name: NATS_PASSWORD
|
||||
value: "Pac
|
||||
- name: INTERNAL_API_KEY
|
||||
value: "doormile-internal-2024"
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: doormile-secrets
|
||||
key: NATS_PASSWORD
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: doormile-service
|
||||
namespace: doormile
|
||||
labels:
|
||||
app: doormile
|
||||
spec:
|
||||
type: NodePort
|
||||
selector:
|
||||
app-group: doormile-api
|
||||
ports:
|
||||
- protocol: TCP
|
||||
port: 8081
|
||||
targetPort: 808
|
||||
nodePort: 30830
|
||||
port: 8081 # Expose port 8081 internally
|
||||
targetPort: 8081 # The port the backend application actually listens on
|
||||
nodePort: 30830 # This must match what NGINX is looking for
|
||||
|
||||
@@ -1,61 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: atlantis
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: atlantis
|
||||
spec:
|
||||
serviceName: "atlantis"
|
||||
replicas: 2
|
||||
selector:
|
||||
matchLabels:
|
||||
app: atlantis
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: atlantis
|
||||
spec:
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
value: apps
|
||||
effect: NoSchedule
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.workolik/app
|
||||
operator: In
|
||||
values:
|
||||
- "true"
|
||||
podAntiAffinity:
|
||||
preferredDuringSchedulingIgnoredDuringExecution:
|
||||
- weight: 100
|
||||
podAffinityTerm:
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: atlantis
|
||||
topologyKey: kubernetes.io/hostname
|
||||
topologySpreadConstraints:
|
||||
- maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: atlantis
|
||||
containers:
|
||||
- name: backend
|
||||
image: nearlecommerce/atlantis:v0.0.41
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
env:
|
||||
- name: PORT
|
||||
value: "3000"
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: nearle-config
|
||||
- secretRef:
|
||||
name: app-secrets
|
||||
@@ -1,16 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: atlantis
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: atlantis
|
||||
spec:
|
||||
type: NodePort
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 3000
|
||||
nodePort: 30825
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: atlantis
|
||||
@@ -1,99 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: fiesta
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: fiesta
|
||||
spec:
|
||||
serviceName: "fiesta"
|
||||
replicas: 3
|
||||
selector:
|
||||
matchLabels:
|
||||
app: fiesta
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: fiesta
|
||||
spec:
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
value: apps
|
||||
effect: NoSchedule
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.workolik/app
|
||||
operator: In
|
||||
values:
|
||||
- "true"
|
||||
podAntiAffinity:
|
||||
preferredDuringSchedulingIgnoredDuringExecution:
|
||||
- weight: 100
|
||||
podAffinityTerm:
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: fiesta
|
||||
topologyKey: kubernetes.io/hostname
|
||||
topologySpreadConstraints:
|
||||
- maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: fiesta
|
||||
containers:
|
||||
- name: backend
|
||||
image: nearlecommerce/fiesta:v1.3.67
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- containerPort: 1122
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: nearle-config
|
||||
- secretRef:
|
||||
name: app-secrets
|
||||
env:
|
||||
- name: PORT
|
||||
value: "1122"
|
||||
- name: NATS_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: nats-credentials
|
||||
key: username
|
||||
- name: NATS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: nats-credentials
|
||||
key: password
|
||||
- name: gateway
|
||||
image: workolik360/alaska:v1.2.0
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
name: http
|
||||
volumeMounts:
|
||||
- name: gateway-script
|
||||
mountPath: /app/app.py
|
||||
subPath: app.py
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: nearle-config
|
||||
env:
|
||||
- name: NATS_USER
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: nats-credentials
|
||||
key: username
|
||||
- name: NATS_PASSWORD
|
||||
valueFrom:
|
||||
secretKeyRef:
|
||||
name: nats-credentials
|
||||
key: password
|
||||
volumes:
|
||||
- name: gateway-script
|
||||
configMap:
|
||||
name: fiesta-gateway-script
|
||||
@@ -1,21 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: fiesta
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: fiesta
|
||||
spec:
|
||||
type: NodePort
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 1122
|
||||
nodePort: 30823
|
||||
protocol: TCP
|
||||
name: main
|
||||
- port: 8000
|
||||
targetPort: 8000
|
||||
name: gateway
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: fiesta
|
||||
@@ -1,77 +0,0 @@
|
||||
apiVersion: apps/v1
|
||||
kind: StatefulSet
|
||||
metadata:
|
||||
name: jupiter
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: jupiter
|
||||
spec:
|
||||
serviceName: "jupiter"
|
||||
replicas: 3
|
||||
selector:
|
||||
matchLabels:
|
||||
app: jupiter
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: jupiter
|
||||
spec:
|
||||
tolerations:
|
||||
- key: dedicated
|
||||
operator: Equal
|
||||
value: apps
|
||||
effect: NoSchedule
|
||||
affinity:
|
||||
nodeAffinity:
|
||||
requiredDuringSchedulingIgnoredDuringExecution:
|
||||
nodeSelectorTerms:
|
||||
- matchExpressions:
|
||||
- key: node-role.workolik/app
|
||||
operator: In
|
||||
values:
|
||||
- "true"
|
||||
podAntiAffinity:
|
||||
preferredDuringSchedulingIgnoredDuringExecution:
|
||||
- weight: 100
|
||||
podAffinityTerm:
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: jupiter
|
||||
topologyKey: kubernetes.io/hostname
|
||||
topologySpreadConstraints:
|
||||
- maxSkew: 1
|
||||
topologyKey: kubernetes.io/hostname
|
||||
whenUnsatisfiable: ScheduleAnyway
|
||||
labelSelector:
|
||||
matchLabels:
|
||||
app: jupiter
|
||||
containers:
|
||||
- name: jupiter
|
||||
image: nearlecommerce/jupiter:v2.7.53
|
||||
imagePullPolicy: Always
|
||||
ports:
|
||||
- containerPort: 1009
|
||||
env:
|
||||
- name: PORT
|
||||
value: "1009"
|
||||
- name: TZ
|
||||
value: "Asia/Kolkata"
|
||||
volumeMounts:
|
||||
- name: tz-config
|
||||
mountPath: /etc/localtime
|
||||
readOnly: true
|
||||
- name: tz-data
|
||||
mountPath: /usr/share/zoneinfo
|
||||
readOnly: true
|
||||
envFrom:
|
||||
- configMapRef:
|
||||
name: nearle-config
|
||||
- secretRef:
|
||||
name: app-secrets
|
||||
volumes:
|
||||
- name: tz-config
|
||||
hostPath:
|
||||
path: /usr/share/zoneinfo/Asia/Kolkata
|
||||
- name: tz-data
|
||||
hostPath:
|
||||
path: /usr/share/zoneinfo
|
||||
@@ -1,16 +0,0 @@
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: jupiter
|
||||
namespace: nearle
|
||||
labels:
|
||||
app: jupiter
|
||||
spec:
|
||||
type: NodePort
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 1009
|
||||
nodePort: 30822
|
||||
protocol: TCP
|
||||
selector:
|
||||
app: jupiter
|
||||
@@ -49,6 +49,11 @@ spec:
|
||||
- name: backend
|
||||
image: nearlecommerce/ariane:v1.0.22
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 1000
|
||||
env:
|
||||
|
||||
@@ -49,6 +49,11 @@ spec:
|
||||
- name: backend
|
||||
image: nearlecommerce/atlantis:v0.0.41
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 3000
|
||||
env:
|
||||
|
||||
@@ -47,8 +47,13 @@ spec:
|
||||
app: fiesta
|
||||
containers:
|
||||
- name: backend
|
||||
image: nearlecommerce/fiesta:v1.3.50
|
||||
image: nearlecommerce/fiesta:v1.3.78
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 1122
|
||||
envFrom:
|
||||
@@ -72,6 +77,11 @@ spec:
|
||||
- name: gateway
|
||||
image: workolik360/alaska:v1.2.0
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 8000
|
||||
name: http
|
||||
|
||||
@@ -47,8 +47,13 @@ spec:
|
||||
app: jupiter
|
||||
containers:
|
||||
- name: jupiter
|
||||
image: nearlecommerce/jupiter:v2.7.31
|
||||
image: nearlecommerce/jupiter:v2.7.55
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 1009
|
||||
env:
|
||||
|
||||
@@ -49,6 +49,11 @@ spec:
|
||||
- name: backend
|
||||
image: groomgear/groomgear:v1.0.41
|
||||
imagePullPolicy: Always
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
ports:
|
||||
- containerPort: 1006
|
||||
---
|
||||
|
||||
Reference in New Issue
Block a user