Skip to main content

Security guidance

Shared responsibility​

LoadoutHQ secures the application and publishes immutable artifacts. The operator secures Kubernetes, ingress, identity, PostgreSQL, external or bundled Valkey, object storage, registry credentials, backups, and network boundaries.

Required controls​

  • Terminate TLS at ingress and redirect HTTP to HTTPS.
  • Restrict dependencies to the application network.
  • Store credentials and licenses in Kubernetes Secrets or an external secret manager.
  • Use dedicated, least-privilege database and storage credentials.
  • Pin production images to a release tag or digest; never deploy latest.
  • Restrict namespace access, kubectl exec, logs, and Secret reads.
  • Enable audit logging and use a trusted time source.

The chart defaults to non-root containers, read-only root filesystems, dropped capabilities, and seccomp. Review any override that weakens these settings.

Network policy​

The parent chart does not create a NetworkPolicy because ingress, DNS, and external endpoints vary. Operators should allow ingress-controller traffic to web; API egress to PostgreSQL, Valkey, S3, OIDC, and DNS; and worker egress to PostgreSQL, Valkey, S3, and DNS. When bundled Valkey is enabled, configure valkey.networkPolicy for the cluster's pod-label and DNS policy. Deny other traffic according to local policy.

Secret rotation​

Rotate one dependency credential at a time, update it through the approved secret workflow, let GitOps reconcile affected workloads, and validate readiness before removing the old credential. Follow Licensing when replacing a customer license.

Reporting​

Provide versions, sanitized events, and error codes. Never attach license files, tokens, passwords, database URLs, or complete environment dumps.