Skip to content

dev-cluster: document accepted dev-only security tradeoffs - #1

Merged
krlex merged 1 commit into
mainfrom
security-hardening-2026-07
Jul 16, 2026
Merged

dev-cluster: document accepted dev-only security tradeoffs#1
krlex merged 1 commit into
mainfrom
security-hardening-2026-07

Conversation

@krlex

@krlex krlex commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Flag the hardcoded join token, world-readable synced kubeconfig and unpinned k3s install as deliberate local-dev conveniences (L19/L20), not to be reused or exposed outside the throwaway Vagrant cluster.

Summary

Motivation

Changes

Testing

  • Existing tests pass locally
  • New tests added (where applicable)
  • Manual verification documented above

Notes for reviewers

Checklist

  • Commits are signed with a real name and email
  • CHANGELOG.md updated (under ## [Unreleased])
  • Documentation updated (README / docs/ / Pages) if behavior changed
  • No secrets, credentials, or internal hostnames committed

Flag the hardcoded join token, world-readable synced kubeconfig and unpinned
k3s install as deliberate local-dev conveniences (L19/L20), not to be reused
or exposed outside the throwaway Vagrant cluster.
@krlex
krlex merged commit e31ee5b into main Jul 16, 2026
1 check passed
@krlex
krlex deleted the security-hardening-2026-07 branch July 30, 2026 14:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant