2026-10-03 16:00:22 -05:00
|
|
|
# Default deployment permissions
|
|
|
|
|
|
|
|
|
|
This deployment uses the Longhorn backend. It reads inventory across namespaces
|
|
|
|
|
and updates only `soteria-policies` and `soteria-backup-usage` in its own namespace.
|
|
|
|
|
The empty Secret declarations create those records on first deployment; they
|
|
|
|
|
deliberately contain no data field, so application-written state is preserved.
|
|
|
|
|
The optional `soteria-restic` credential is readable by exact name only.
|
|
|
|
|
|
|
|
|
|
Changing the state or credential names also requires updating the Role. Do not
|
|
|
|
|
restore cluster-wide Secret access to accommodate another deployment.
|
|
|
|
|
|
|
|
|
|
The optional restic backend needs additional, explicitly approved Roles and
|
|
|
|
|
RoleBindings in each backup/restore target namespace: Job creation and the
|
|
|
|
|
credential-copy operations in `internal/k8s/jobs.go`. Those grants are not part
|
|
|
|
|
of this Longhorn deployment. Review credential distribution before enabling
|
|
|
|
|
restic; Kubernetes RBAC cannot restrict Secret creation by resource name.
|
2026-10-04 06:25:27 -05:00
|
|
|
|
|
|
|
|
## CI image construction
|
|
|
|
|
|
|
|
|
|
Jenkins compiles the UI and ARM64 Go binary in its `ci-scratch` workspace PVC.
|
|
|
|
|
Compiler and package caches also use that PVC. The final Kaniko step receives
|
|
|
|
|
only `build/image/` and `Dockerfile.runtime`, so it packages the binary without
|
|
|
|
|
unpacking Node/Go toolchains or compiling on the node's runtime filesystem.
|
|
|
|
|
The ordinary multistage `Dockerfile` remains available for workstation builds.
|
|
|
|
|
|
|
|
|
|
Keep `CGO_ENABLED=0`, the UI embedding step and the runtime architecture aligned.
|
|
|
|
|
The runtime image stays nonroot and exposes the same port and entrypoint. Image
|
|
|
|
|
publication still requires all existing quality and supply-chain gates.
|