Skip to content

James/security enhancements CEL policy update#83

Open
JPurcell-Braintrust wants to merge 3 commits intomainfrom
james/security-enhancements
Open

James/security enhancements CEL policy update#83
JPurcell-Braintrust wants to merge 3 commits intomainfrom
james/security-enhancements

Conversation

@JPurcell-Braintrust
Copy link
Copy Markdown

Adding in the previous security enhancements to fix CEL based policy breaches, previously based on 1.1.32 to the latest helm updates. The security enhancements were:

  • add securityContext and podSecurityContext to all 3 pod types
  • readOnlyRootFilesystem
  • emptyDir size limits for Brainstore volumes

An example/google-autopilot-cel/ has been created to help the known customers currently needing these CEL enhancements in their production environment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant