argocd, cert-manager, cloudnative-pg already compliant — label flip only.
ocis: add overlay injecting seccompProfile=RuntimeDefault, drop ALL caps,
allowPrivilegeEscalation=false across all chart Deployments/CronJobs;
patch idm initContainer; harden custom precheck Job; refactor s3-backup
to rclone/rclone image (avoids apk-add-as-root).
victoria-metrics-single: overlay sets full restricted SC on the StatefulSet
that ships with empty securityContext: {}.
forgejo, traefik, kube-system stay privileged (hostPort / CSI driver).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| argocd | ||
| cert-manager | ||
| cloudnative-pg | ||
| forgejo | ||
| grafana | ||
| hcloud-csi | ||
| kube-state-metrics | ||
| kubernetes-secret-generator | ||
| metrics-server | ||
| node-exporter | ||
| ocis | ||
| traefik | ||
| victoria-metrics-single | ||