Skip to content

Harden helm charts, better defaults, secrets management, etc#3243

Merged
crivetimihai merged 12 commits intomainfrom
harden-helm
Feb 25, 2026
Merged

Harden helm charts, better defaults, secrets management, etc#3243
crivetimihai merged 12 commits intomainfrom
harden-helm

Conversation

@crivetimihai
Copy link
Copy Markdown
Member

Harden helm charts, better defaults, secrets management, etc

@crivetimihai crivetimihai self-assigned this Feb 25, 2026
@crivetimihai crivetimihai added the security Improves security label Feb 25, 2026
@crivetimihai crivetimihai added this to the Release 1.0.0-RC2 milestone Feb 25, 2026
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
@crivetimihai crivetimihai marked this pull request as ready for review February 25, 2026 10:17
@crivetimihai crivetimihai merged commit 8ba7a6d into main Feb 25, 2026
49 checks passed
@crivetimihai crivetimihai deleted the harden-helm branch February 25, 2026 10:17
vishu-bh pushed a commit that referenced this pull request Feb 25, 2026
* docs: record chart upgrade guidance and new helm resource defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(charts): harden postgres upgrade safety and document rules

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix: tune chart probe timings for high-load stability

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: reduce token exposure and consolidate postgres secrets

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: disable pgadmin and redis commander by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: enable redis auth with secret-backed credentials

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden workloads and enable default network policies

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden ingress tls defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(chart): require auth for MCP endpoint by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* docs(helm): document SSRF requirements for in-cluster tool registration

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update packages

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update docs

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

---------

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
vishu-bh pushed a commit that referenced this pull request Feb 25, 2026
* docs: record chart upgrade guidance and new helm resource defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(charts): harden postgres upgrade safety and document rules

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix: tune chart probe timings for high-load stability

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: reduce token exposure and consolidate postgres secrets

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: disable pgadmin and redis commander by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: enable redis auth with secret-backed credentials

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden workloads and enable default network policies

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden ingress tls defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(chart): require auth for MCP endpoint by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* docs(helm): document SSRF requirements for in-cluster tool registration

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update packages

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update docs

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

---------

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
MohanLaksh pushed a commit that referenced this pull request Mar 12, 2026
* docs: record chart upgrade guidance and new helm resource defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(charts): harden postgres upgrade safety and document rules

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix: tune chart probe timings for high-load stability

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: reduce token exposure and consolidate postgres secrets

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: disable pgadmin and redis commander by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* hardening: enable redis auth with secret-backed credentials

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden workloads and enable default network policies

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* feat(charts): harden ingress tls defaults

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* fix(chart): require auth for MCP endpoint by default

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* docs(helm): document SSRF requirements for in-cluster tool registration

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update packages

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

* Update docs

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>

---------

Signed-off-by: Mihai Criveti <crivetimihai@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Improves security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant