feat: harden self-managed reconciliation
This commit is contained in:
@@ -28,6 +28,20 @@ a per-project namespace, reconciles managed Postgres and S3 claims, rolls
|
||||
deployments back, streams logs, and exposes interactive `exec` sessions over a
|
||||
WebSocket.
|
||||
|
||||
## Directory Trust
|
||||
|
||||
Before `kuber up`, run `kuber trust` from the configured project directory.
|
||||
Trust is exactly the configured namespace plus a SHA-256 fingerprint of the
|
||||
resolved current working directory. The local mode-0600 store lets `up` fail
|
||||
before builds from an untrusted directory. The server stores only namespace and
|
||||
fingerprint registrations in labelled ConfigMaps in its `kuber-system` control
|
||||
plane namespace, then checks the pair when resource reconciliation begins.
|
||||
|
||||
This is an accidental-targeting safeguard, not a security boundary: a client
|
||||
that intentionally forges a registered fingerprint can pass it. `kuber trust
|
||||
status` shows local/server awareness without printing paths; `kuber trust revoke`
|
||||
removes the current directory registration.
|
||||
|
||||
## Environment Assumptions
|
||||
|
||||
kuber targets a specific self-hosted cluster and workstation setup. It is not
|
||||
|
||||
Reference in New Issue
Block a user