mirror of
https://github.com/semantica-agi/semantica.git
synced 2026-08-29 04:26:20 +00:00
- gcp/cloudrun-service.yaml: add comment + README sed one-liner so PROJECT_ID
is substituted before gcloud run services replace (was a literal placeholder
that caused image-pull failure on the declarative deploy path)
- azure/main.parameters.json: replace wildcard allowedOrigins "*" with a
REPLACE_ME placeholder; add README note to set the real URL after first deploy
- kubernetes/networkpolicy.yaml + helm networkpolicy template: add from: selector
(ingress-nginx namespace + same-namespace pods) so ingress is no longer
allow-all; restrict egress to FalkorDB port 6379 and DNS port 53 instead of
the allow-all egress: - {} wildcard
- helm/values.yaml: expose networkPolicy.ingressNamespace and falkordbPort values
- kubernetes/deployment.yaml: add secretRef for knowledge-explorer-secrets so
FALKORDB_PASSWORD is actually injected into the container
- app.py: add _mutation_bridge_installed guard to prevent closure stacking when
the same GraphSession is passed to create_app() more than once; remove
duplicate app.state.allowed_origins assignment (single source of truth is
app.state.explorer_settings); add comment on falkordb_host/port dead config
- tests: update allowed_origins assertions to use explorer_settings dict
- .checkov.yaml: remove global CKV_K8S_21/28/30 suppressions; rely on per-file
inline checkov:skip comments in cloudrun-service.yaml so future real K8s
manifests are not silently exempted
31 lines
689 B
JSON
31 lines
689 B
JSON
{
|
|
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#",
|
|
"contentVersion": "1.0.0.0",
|
|
"parameters": {
|
|
"environmentName": {
|
|
"value": "${AZURE_ENV_NAME}"
|
|
},
|
|
"location": {
|
|
"value": "${AZURE_LOCATION}"
|
|
},
|
|
"imageName": {
|
|
"value": "${SERVICE_EXPLORER_IMAGE_NAME}"
|
|
},
|
|
"allowedOrigins": {
|
|
"value": "https://REPLACE_ME.azurecontainerapps.io"
|
|
},
|
|
"falkordbHost": {
|
|
"value": "falkordb"
|
|
},
|
|
"falkordbPort": {
|
|
"value": "6379"
|
|
},
|
|
"vnetInternal": {
|
|
"value": true
|
|
},
|
|
"infrastructureSubnetId": {
|
|
"value": "${AZURE_INFRASTRUCTURE_SUBNET_ID}"
|
|
}
|
|
}
|
|
}
|