feat: harden self-managed reconciliation

This commit is contained in:
2026-09-05 10:17:55 +00:00 Unverified
parent 8e9d207915
commit 321f4e807a
40 changed files with 4977 additions and 404 deletions
+14
View File
@@ -28,6 +28,20 @@ a per-project namespace, reconciles managed Postgres and S3 claims, rolls
deployments back, streams logs, and exposes interactive `exec` sessions over a
WebSocket.
## Directory Trust
Before `kuber up`, run `kuber trust` from the configured project directory.
Trust is exactly the configured namespace plus a SHA-256 fingerprint of the
resolved current working directory. The local mode-0600 store lets `up` fail
before builds from an untrusted directory. The server stores only namespace and
fingerprint registrations in labelled ConfigMaps in its `kuber-system` control
plane namespace, then checks the pair when resource reconciliation begins.
This is an accidental-targeting safeguard, not a security boundary: a client
that intentionally forges a registered fingerprint can pass it. `kuber trust
status` shows local/server awareness without printing paths; `kuber trust revoke`
removes the current directory registration.
## Environment Assumptions
kuber targets a specific self-hosted cluster and workstation setup. It is not