Skip to content

feat: Enhance security contexts, network policies, and resource quotas#443

Draft
LuukvH wants to merge 1 commit into
mainfrom
feat-security
Draft

feat: Enhance security contexts, network policies, and resource quotas#443
LuukvH wants to merge 1 commit into
mainfrom
feat-security

Conversation

@LuukvH
Copy link
Copy Markdown
Collaborator

@LuukvH LuukvH commented Sep 12, 2025

feat: Add volume mounts and update nginx configuration for improved caching and security

feat: Update rate limit filter to use rate_limit_quota for improved quota management

feat: Add NET_BIND_SERVICE capability to web container for enhanced networking

feat: Increase CPU limit from 4 to 8 for resource quota in production

feat: Remove rate limit quota filter from Envoy configuration

feat: Update web application to use port 8080 for HTTP and NGINX configuration

feat: Remove unnecessary user and group creation for NGINX in Dockerfile

feat: Simplify NGINX setup by removing unnecessary libcap installation and updating pid location for non-root execution

feat: Update NGINX pid file location to use /var/run for Kubernetes deployment

feat: Add NetworkPolicy to allow Envoy egress traffic to CRM and scheduling APIs

feat: Update CRM deployment and service to use port 8080 for HTTP traffic

feat: Add NetworkPolicies for RabbitMQ egress traffic to backends and scheduling APIs

fix: Correct order of resources in kustomization.yaml for network policies

feat: Update Ingress configuration to route traffic to web service on port 8080

fix: Update web service to use port 80 for HTTP traffic in deployment, service, ingress, and network policy

fix: Adjust ingress rules in allow-web-ingress.yaml to properly define source namespace for web traffic

fix: Update deployment and service configurations to use port 8080 for HTTP traffic

feat: Add volume mounts and update nginx configuration for improved caching and security

feat: Update rate limit filter to use rate_limit_quota for improved quota management

feat: Add NET_BIND_SERVICE capability to web container for enhanced networking

feat: Increase CPU limit from 4 to 8 for resource quota in production

feat: Remove rate limit quota filter from Envoy configuration

feat: Update web application to use port 8080 for HTTP and NGINX configuration

feat: Remove unnecessary user and group creation for NGINX in Dockerfile

feat: Simplify NGINX setup by removing unnecessary libcap installation and updating pid location for non-root execution

feat: Update NGINX pid file location to use /var/run for Kubernetes deployment

feat: Add NetworkPolicy to allow Envoy egress traffic to CRM and scheduling APIs

feat: Update CRM deployment and service to use port 8080 for HTTP traffic

feat: Add NetworkPolicies for RabbitMQ egress traffic to backends and scheduling APIs

fix: Correct order of resources in kustomization.yaml for network policies

feat: Update Ingress configuration to route traffic to web service on port 8080

fix: Update web service to use port 80 for HTTP traffic in deployment, service, ingress, and network policy

fix: Adjust ingress rules in allow-web-ingress.yaml to properly define source namespace for web traffic

fix: Update deployment and service configurations to use port 8080 for HTTP traffic
@LuukvH LuukvH force-pushed the main branch 9 times, most recently from 4930201 to 587aa33 Compare September 12, 2025 20:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant