chore(langfuse): set pod security standards

This commit is contained in:
Masaki Yatsu
2025-12-01 17:22:00 +09:00
parent 05f8489d3d
commit d02701d5c1
3 changed files with 43 additions and 2 deletions

View File

@@ -1,4 +1,21 @@
langfuse:
# Pod Security Context (restricted PSS compliant)
podSecurityContext:
runAsNonRoot: true
runAsUser: 1001
runAsGroup: 1001
fsGroup: 1001
seccompProfile:
type: RuntimeDefault
# Container Security Context (restricted PSS compliant)
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: false
salt:
value: {{ .Env.LANGFUSE_SALT }}
features: