ci,k8s: harden workflow permissions, pin actions, and lock down container security context #1

Open
jhgaylor wants to merge 1 commit from mend/chant-audit-mt1yr8hm into main
Owner

Moved from https://github.com/jhgaylor/otfl/pull/2 (the repo now lives on Forgejo).

Note: this edits .github/workflows/build.yml, which moved to .forgejo/workflows/build.yml, so that part needs porting before merge.


A chant audit flagged 10 merge-worthy findings on the build workflow and k8s/deployment.yaml; this covers the three you picked.

  • Top-level workflow permissions (GHA017) — added permissions: contents: read for least privilege.
  • Pin Docker actions to commit SHAs (GHA029) — resolved setup-qemu-action, setup-buildx-action, login-action (v3) and build-push-action (v6) to commit SHAs, kept as trailing comments.
  • Harden container security context (WK8203, WK8204, WK8205) — added runAsNonRoot: true, readOnlyRootFilesystem: true, and capabilities.drop: [ALL]; this one wants review — verified the app only writes to the DATA_DIR PVC mount, but please confirm before merging.
Moved from https://github.com/jhgaylor/otfl/pull/2 (the repo now lives on Forgejo). Note: this edits `.github/workflows/build.yml`, which moved to `.forgejo/workflows/build.yml`, so that part needs porting before merge. --- A `chant audit` flagged 10 merge-worthy findings on the `build` workflow and `k8s/deployment.yaml`; this covers the three you picked. - **Top-level workflow permissions** (GHA017) — added `permissions: contents: read` for least privilege. - **Pin Docker actions to commit SHAs** (GHA029) — resolved setup-qemu-action, setup-buildx-action, login-action (v3) and build-push-action (v6) to commit SHAs, kept as trailing comments. - **Harden container security context** (WK8203, WK8204, WK8205) — added `runAsNonRoot: true`, `readOnlyRootFilesystem: true`, and `capabilities.drop: [ALL]`; this one wants review — verified the app only writes to the DATA_DIR PVC mount, but please confirm before merging.
This pull request has changes conflicting with the target branch.
  • .github/workflows/build.yml
  • k8s/deployment.yaml
View command line instructions

Manual merge helper

Use this merge commit message when completing the merge manually.

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin mend/chant-audit-mt1yr8hm:mend/chant-audit-mt1yr8hm
git switch mend/chant-audit-mt1yr8hm

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff mend/chant-audit-mt1yr8hm
git switch mend/chant-audit-mt1yr8hm
git rebase main
git switch main
git merge --ff-only mend/chant-audit-mt1yr8hm
git switch mend/chant-audit-mt1yr8hm
git rebase main
git switch main
git merge --no-ff mend/chant-audit-mt1yr8hm
git switch main
git merge --squash mend/chant-audit-mt1yr8hm
git switch main
git merge --ff-only mend/chant-audit-mt1yr8hm
git switch main
git merge mend/chant-audit-mt1yr8hm
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
jhgaylor/otfl!1
No description provided.