fix(media): fix kaizoku convention violations #196

Merged
Exikle merged 1 commit from fix/media-kaizoku-conventions into main 2026-06-03 11:30:00 +00:00
Owner
No description provided.
fix(media): fix kaizoku convention violations
Some checks failed
Labeler / Labeler (pull_request_target) Successful in 45s
Flate / Flate - Filter (pull_request) Successful in 20s
Flate / Flate (helmrelease) (pull_request) Failing after 4m25s
Flate / Flate (kustomization) (pull_request) Failing after 4m45s
Flate - Success Flate checks failure
Flate / Flate - Success (pull_request) Failing after 32s
9ad43d5aa4
- Add runAsNonRoot/runAsUser/runAsGroup to defaultPodOptions (uid 99, gid 100)
- Add container securityContext (allowPrivilegeEscalation, capabilities, readOnlyRootFilesystem)
- Add tmp emptyDir for readOnlyRootFilesystem
- Fix env field order (PGID before PUID)
- Add retryInterval: 1m to ks.yaml
- Remove stale onepassword-connect dependsOn (no ExternalSecret)
Exikle scheduled this pull request to auto merge when all checks succeed 2026-06-03 04:58:23 +00:00
Exikle force-pushed fix/media-kaizoku-conventions from 9ad43d5aa4
Some checks failed
Labeler / Labeler (pull_request_target) Successful in 45s
Flate / Flate - Filter (pull_request) Successful in 20s
Flate / Flate (helmrelease) (pull_request) Failing after 4m25s
Flate / Flate (kustomization) (pull_request) Failing after 4m45s
Flate - Success Flate checks failure
Flate / Flate - Success (pull_request) Failing after 32s
to da69e68171
All checks were successful
Flate / Flate - Filter (pull_request) Successful in 15s
Labeler / Labeler (pull_request_target) Successful in 40s
Flate / Flate (kustomization) (pull_request) Successful in 2m41s
Flate / Flate (helmrelease) (pull_request) Successful in 2m59s
Flate - Success Flate checks success
Flate / Flate - Success (pull_request) Successful in 24s
2026-06-03 11:26:18 +00:00
Compare
Collaborator
Kustomization diff
# Kustomization: flux-system/artemis-cluster Kustomization: media/kaizoku

@@ spec.dependsOn @@
! - one list entry removed:
- - name: onepassword-connect
-   namespace: external-secrets

# Kustomization: media/kaizoku HelmRelease: media/kaizoku

@@ spec.values.controllers.kaizoku.containers.app @@
! + one map entry added:
+ securityContext:
+   allowPrivilegeEscalation: false
+   capabilities:
+     drop:
+     - ALL
+   readOnlyRootFilesystem: true

@@ spec.values.defaultPodOptions.securityContext @@
! + three map entries added:
+ runAsGroup: 100
+ runAsNonRoot: true
+ runAsUser: 99

@@ spec.values.persistence @@
! + one map entry added:
+ tmp:
+   type: emptyDir
+   advancedMounts:
+     kaizoku:
+       app:
+       - path: /tmp
+         subPath: tmp

Diff created by flateWorkflow run

<!-- Sticky Pull Request Comment196/kubernetes/kustomization --> <details open><summary>Kustomization diff</summary> ```diff # Kustomization: flux-system/artemis-cluster Kustomization: media/kaizoku @@ spec.dependsOn @@ ! - one list entry removed: - - name: onepassword-connect - namespace: external-secrets # Kustomization: media/kaizoku HelmRelease: media/kaizoku @@ spec.values.controllers.kaizoku.containers.app @@ ! + one map entry added: + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL + readOnlyRootFilesystem: true @@ spec.values.defaultPodOptions.securityContext @@ ! + three map entries added: + runAsGroup: 100 + runAsNonRoot: true + runAsUser: 99 @@ spec.values.persistence @@ ! + one map entry added: + tmp: + type: emptyDir + advancedMounts: + kaizoku: + app: + - path: /tmp + subPath: tmp ``` </details> <sub>Diff created by [flate](https://github.com/home-operations/flate) — [Workflow run](https://git.dcunha.io/Exikle/Artemis-Cluster/actions/runs/748)</sub>
Collaborator
HelmRelease diff
# HelmRelease: media/kaizoku Deployment: media/kaizoku

@@ spec.template.spec.containers.app @@
! + one map entry added:
+ securityContext:
+   allowPrivilegeEscalation: false
+   capabilities:
+     drop:
+     - ALL
+   readOnlyRootFilesystem: true

@@ spec.template.spec.containers.app.volumeMounts @@
! + one list entry added:
+ - name: tmp
+   mountPath: /tmp
+   subPath: tmp

@@ spec.template.spec.securityContext @@
! + three map entries added:
+ runAsGroup: 100
+ runAsNonRoot: true
+ runAsUser: 99

@@ spec.template.spec.volumes @@
! + one list entry added:
+ - name: tmp
+   emptyDir: {}

Diff created by flateWorkflow run

<!-- Sticky Pull Request Comment196/kubernetes/helmrelease --> <details open><summary>HelmRelease diff</summary> ```diff # HelmRelease: media/kaizoku Deployment: media/kaizoku @@ spec.template.spec.containers.app @@ ! + one map entry added: + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL + readOnlyRootFilesystem: true @@ spec.template.spec.containers.app.volumeMounts @@ ! + one list entry added: + - name: tmp + mountPath: /tmp + subPath: tmp @@ spec.template.spec.securityContext @@ ! + three map entries added: + runAsGroup: 100 + runAsNonRoot: true + runAsUser: 99 @@ spec.template.spec.volumes @@ ! + one list entry added: + - name: tmp + emptyDir: {} ``` </details> <sub>Diff created by [flate](https://github.com/home-operations/flate) — [Workflow run](https://git.dcunha.io/Exikle/Artemis-Cluster/actions/runs/748)</sub>
Exikle merged commit c5fc723c9b into main 2026-06-03 11:30:00 +00:00
Exikle deleted branch fix/media-kaizoku-conventions 2026-06-03 11:30:01 +00:00
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Exikle/Artemis-Cluster!196
No description provided.