fix(ci): fix 2 remaining checkov HIGH findings and Terrascan seccomp warnings

The 2 active checkov HIGH results (CKV_K8S_28 + CKV_K8S_30) were coming
from deploy/gcp/cloudrun-service.yaml — checkov scans it as a Kubernetes
resource (apiVersion: serving.knative.dev/v1) and flagged missing AppArmor
and seccomp on that file, regardless of the fixes made to the k8s/ and
helm/ manifests.

deploy/gcp/cloudrun-service.yaml:
- Add container name (explorer) so AppArmor annotation key matches
- Add AppArmor annotation to pod template metadata (CKV_K8S_30)
- Add legacy seccomp annotation (AC_K8S_0080 / CKV_K8S_28)
- Add pod-level seccompProfile: RuntimeDefault (CKV_K8S_28)
- Add container securityContext (runAsNonRoot, allowPrivilegeEscalation)
  Cloud Run Gen 2 supports all of these fields

deploy/kubernetes/deployment.yaml:
- Pin image tag from ':latest' to ':0.5.0' (AC_K8S_0068 / AC_K8S_0069)
- Add legacy seccomp pod annotation alongside existing seccompProfile field

deploy/helm/knowledge-explorer/values.yaml:
- Add legacy seccomp annotation to podAnnotations so it renders into
  the Helm-generated pod template alongside the modern seccompProfile
This commit is contained in:
KaifAhmad1
2026-06-24 13:15:41 +05:30
parent 095e8c8714
commit 8b5f75160a
3 changed files with 17 additions and 2 deletions
+12 -1
View File
@@ -12,11 +12,22 @@ spec:
annotations:
autoscaling.knative.dev/minScale: "0"
autoscaling.knative.dev/maxScale: "10"
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
seccomp.security.alpha.kubernetes.io/pod: runtime/default
spec:
containerConcurrency: 80
timeoutSeconds: 300
securityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
containers:
- image: gcr.io/PROJECT_ID/knowledge-explorer:latest
- name: explorer
image: gcr.io/PROJECT_ID/knowledge-explorer:latest
securityContext:
allowPrivilegeEscalation: false
runAsNonRoot: true
runAsUser: 1000
ports:
- name: http1
containerPort: 8000
@@ -13,6 +13,9 @@ fullnameOverride: ""
podAnnotations:
# AppArmor — must match the container name defined in the Deployment template ("explorer").
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
# Legacy seccomp annotation — required by older Terrascan/checkov versions
# that predate the seccompProfile field in PodSecurityContext.
seccomp.security.alpha.kubernetes.io/pod: runtime/default
podLabels: {}
podSecurityContext:
+2 -1
View File
@@ -20,6 +20,7 @@ spec:
metadata:
annotations:
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
seccomp.security.alpha.kubernetes.io/pod: runtime/default
labels:
app.kubernetes.io/name: knowledge-explorer
app.kubernetes.io/part-of: semantica
@@ -30,7 +31,7 @@ spec:
type: RuntimeDefault
containers:
- name: explorer
image: semantica-knowledge-explorer:latest
image: semantica-knowledge-explorer:0.5.0
imagePullPolicy: IfNotPresent
ports:
- name: http