mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-08-29 04:26:20 +00:00
fix(ci): fix 2 remaining checkov HIGH findings and Terrascan seccomp warnings
The 2 active checkov HIGH results (CKV_K8S_28 + CKV_K8S_30) were coming from deploy/gcp/cloudrun-service.yaml — checkov scans it as a Kubernetes resource (apiVersion: serving.knative.dev/v1) and flagged missing AppArmor and seccomp on that file, regardless of the fixes made to the k8s/ and helm/ manifests. deploy/gcp/cloudrun-service.yaml: - Add container name (explorer) so AppArmor annotation key matches - Add AppArmor annotation to pod template metadata (CKV_K8S_30) - Add legacy seccomp annotation (AC_K8S_0080 / CKV_K8S_28) - Add pod-level seccompProfile: RuntimeDefault (CKV_K8S_28) - Add container securityContext (runAsNonRoot, allowPrivilegeEscalation) Cloud Run Gen 2 supports all of these fields deploy/kubernetes/deployment.yaml: - Pin image tag from ':latest' to ':0.5.0' (AC_K8S_0068 / AC_K8S_0069) - Add legacy seccomp pod annotation alongside existing seccompProfile field deploy/helm/knowledge-explorer/values.yaml: - Add legacy seccomp annotation to podAnnotations so it renders into the Helm-generated pod template alongside the modern seccompProfile
This commit is contained in:
@@ -12,11 +12,22 @@ spec:
|
||||
annotations:
|
||||
autoscaling.knative.dev/minScale: "0"
|
||||
autoscaling.knative.dev/maxScale: "10"
|
||||
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
|
||||
seccomp.security.alpha.kubernetes.io/pod: runtime/default
|
||||
spec:
|
||||
containerConcurrency: 80
|
||||
timeoutSeconds: 300
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- image: gcr.io/PROJECT_ID/knowledge-explorer:latest
|
||||
- name: explorer
|
||||
image: gcr.io/PROJECT_ID/knowledge-explorer:latest
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
ports:
|
||||
- name: http1
|
||||
containerPort: 8000
|
||||
|
||||
@@ -13,6 +13,9 @@ fullnameOverride: ""
|
||||
podAnnotations:
|
||||
# AppArmor — must match the container name defined in the Deployment template ("explorer").
|
||||
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
|
||||
# Legacy seccomp annotation — required by older Terrascan/checkov versions
|
||||
# that predate the seccompProfile field in PodSecurityContext.
|
||||
seccomp.security.alpha.kubernetes.io/pod: runtime/default
|
||||
podLabels: {}
|
||||
|
||||
podSecurityContext:
|
||||
|
||||
@@ -20,6 +20,7 @@ spec:
|
||||
metadata:
|
||||
annotations:
|
||||
container.apparmor.security.beta.kubernetes.io/explorer: runtime/default
|
||||
seccomp.security.alpha.kubernetes.io/pod: runtime/default
|
||||
labels:
|
||||
app.kubernetes.io/name: knowledge-explorer
|
||||
app.kubernetes.io/part-of: semantica
|
||||
@@ -30,7 +31,7 @@ spec:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: explorer
|
||||
image: semantica-knowledge-explorer:latest
|
||||
image: semantica-knowledge-explorer:0.5.0
|
||||
imagePullPolicy: IfNotPresent
|
||||
ports:
|
||||
- name: http
|
||||
|
||||
Reference in New Issue
Block a user