Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PAAS improvements #231

Open
9 of 11 tasks
treydock opened this issue Apr 3, 2024 · 0 comments
Open
9 of 11 tasks

PAAS improvements #231

treydock opened this issue Apr 3, 2024 · 0 comments

Comments

@treydock
Copy link
Contributor

treydock commented Apr 3, 2024

  • Force spec.securityContext.runAsNonRoot and spec.containers[].securityContext
  • Validate service account authorized for account at namespace level
  • Add imagePullSecrets value for "osc-registry" if that resource is present
  • Namespace should authorize the DNS records in OSC domains
  • Add annotations to Ingress
  • Add Ingress class for NGINX usage
  • Disallow services of type LoadBalancer, ExternalName and NodePort.
  • Disallow external-dns annotations ref
  • Disallow hostPort usage ref
  • Add app label if not set
  • Add pod anti affinity if not defined
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant