- talos/: generated base config (gitignored) + patches for control-plane scheduling, unprivileged ports and the ingress firewall - kubernetes/: sish base and cirrus-dev overlay, applied with kubectl - READMEs incl. production rollout plan Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
10 lines
297 B
YAML
10 lines
297 B
YAML
apiVersion: v1
|
|
kind: Namespace
|
|
metadata:
|
|
name: sish
|
|
labels:
|
|
# hostNetwork is only permitted by the privileged profile.
|
|
# The pod itself still runs non-root with all capabilities dropped.
|
|
pod-security.kubernetes.io/enforce: privileged
|
|
pod-security.kubernetes.io/audit: baseline
|