1.6 KiB
Default deployment permissions
This deployment uses the Longhorn backend. It reads inventory across namespaces
and updates only soteria-policies and soteria-backup-usage in its own namespace.
The empty Secret declarations create those records on first deployment; they
deliberately contain no data field, so application-written state is preserved.
The optional soteria-restic credential is readable by exact name only.
Changing the state or credential names also requires updating the Role. Do not restore cluster-wide Secret access to accommodate another deployment.
The optional restic backend needs additional, explicitly approved Roles and
RoleBindings in each backup/restore target namespace: Job creation and the
credential-copy operations in internal/k8s/jobs.go. Those grants are not part
of this Longhorn deployment. Review credential distribution before enabling
restic; Kubernetes RBAC cannot restrict Secret creation by resource name.
CI image construction
Jenkins compiles the UI and ARM64 Go binary in its ci-scratch workspace PVC.
Compiler and package caches also use that PVC. The final Kaniko step receives
only build/image/ and Dockerfile.runtime, so it packages the binary without
unpacking Node/Go toolchains or compiling on the node's runtime filesystem.
The ordinary multistage Dockerfile remains available for workstation builds.
Keep CGO_ENABLED=0, the UI embedding step and the runtime architecture aligned.
The runtime image stays nonroot and exposes the same port and entrypoint. Image
publication still requires all existing quality and supply-chain gates.