#!/usr/bin/env bash # Lints the chart and asserts the load-bearing rendered properties: the # broker rides as a server sidecar sharing the socket volume, SSE is # unbuffered at the ingress, and pods run hardened. set -euo pipefail ROOT="$(cd "$(dirname "$0")/.." && pwd)" CHART="$ROOT/deploy/helm/clawmates" helm lint "$CHART" \ --set auth.issuerUrl=https://idp.example.com \ --set oauth.redirectBase=https://app.clawmates.work RENDERED=$(helm template clawmates "$CHART" \ --set auth.issuerUrl=https://idp.example.com \ --set oauth.redirectBase=https://app.clawmates.work) require() { if ! grep -qF -- "$1" <<<"$RENDERED"; then echo "FAIL: rendered chart is missing: $1" exit 1 fi } # Broker sidecar shares the unix-socket emptyDir with the server. require 'name: broker' require 'value: /run/clawmates/broker.sock' require 'mountPath: /run/clawmates' # SSE must not buffer at the ingress. require 'nginx.ingress.kubernetes.io/proxy-buffering: "off"' # Hardened pods. require 'runAsNonRoot: true' require 'drop: ["ALL"]' require 'readOnlyRootFilesystem: true' # Config wired through the ConfigMap. require 'socket_path = "/run/clawmates/broker.sock"' # The chart-shipped seccomp profile must BE the Docker driver's profile. if ! diff -q "$ROOT/images/seccomp/agent-profile.json" \ "$CHART/files/agent-profile.json" >/dev/null; then echo "FAIL: chart seccomp profile diverged from images/seccomp" exit 1 fi HARDENED=$(helm template clawmates "$CHART" \ --set auth.issuerUrl=https://idp.example.com \ --set oauth.redirectBase=https://app.clawmates.work \ --set sandbox.seccomp=localhost \ --set server.autoscaling.enabled=true) for needle in \ 'kind: DaemonSet' \ 'clawmates-agent-profile.json' \ 'kind: HorizontalPodAutoscaler' \ 'averageUtilization: 70'; do if ! grep -qF -- "$needle" <<<"$HARDENED"; then echo "FAIL: hardened render is missing: $needle" exit 1 fi done echo "helm chart OK"