Fix DDNS/failover Cloudflare zone name and add restricted PSS securityContext

- ZONE_NAME was "kube.huskypup.net" in both the home-ip-ddns CronJob and
  the VPS failover watcher - that's a record, not a Cloudflare zone (the
  actual zone is the parent "huskypup.net"). Caused home-ip-ddns to fail
  every run (zone lookup returned zero results, curl -f exit 22) -
  confirmed live and fixed.
- Added seccompProfile/non-root/dropped-capabilities securityContext to
  the three CronJobs added this session that were missing it (flagged by
  the cluster's "restricted" PodSecurity admission). Repointed the raft
  snapshot job's mc binary install from /usr/local/bin to /tmp so it
  still works running as non-root.
This commit is contained in:
Scooby Husky
2026-08-17 15:55:47 -05:00
parent 983671ef50
commit ee71e4f46f
4 changed files with 28 additions and 7 deletions
@@ -60,6 +60,11 @@ spec:
template:
spec:
restartPolicy: Never
securityContext:
runAsNonRoot: true
runAsUser: 65534
seccompProfile:
type: RuntimeDefault
affinity:
podAffinity:
requiredDuringSchedulingIgnoredDuringExecution:
@@ -70,6 +75,10 @@ spec:
containers:
- name: restic-backup
image: restic/restic:0.16.4
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
command:
- /bin/sh
- -c
@@ -17,7 +17,7 @@ data:
#!/bin/sh
set -eu
ZONE_NAME="kube.huskypup.net"
ZONE_NAME="huskypup.net" # Cloudflare zone is the parent domain - kube.huskypup.net is just a record within it, not its own zone
RECORD_NAME="home.kube.huskypup.net"
TOKEN="$(cat /etc/cf/cloudflare-token)"
@@ -75,6 +75,8 @@ spec:
securityContext:
runAsNonRoot: true
runAsUser: 65534
seccompProfile:
type: RuntimeDefault
containers:
- name: ddns-update
image: alpine/k8s:1.32.13 # already has curl + jq (see MEMORY.md kubectl image note)
@@ -60,17 +60,18 @@ data:
kubectl -n vault exec vault-0 -- rm -f "/tmp/${SNAP_NAME}"
echo "==> Installing mc (MinIO client)..."
curl -sf https://dl.min.io/client/mc/release/linux-amd64/mc -o /usr/local/bin/mc
chmod +x /usr/local/bin/mc
mc alias set vps-minio "http://${VPS_MINIO_ENDPOINT}" \
curl -sf https://dl.min.io/client/mc/release/linux-amd64/mc -o /tmp/mc
chmod +x /tmp/mc
export MC_CONFIG_DIR=/tmp/.mc
/tmp/mc alias set vps-minio "http://${VPS_MINIO_ENDPOINT}" \
"${MINIO_ACCESS_KEY}" "${MINIO_SECRET_KEY}" >/dev/null
echo "==> Uploading ${SNAP_NAME} to vps-minio/${BUCKET}..."
mc cp "/tmp/${SNAP_NAME}" "vps-minio/${BUCKET}/${SNAP_NAME}"
/tmp/mc cp "/tmp/${SNAP_NAME}" "vps-minio/${BUCKET}/${SNAP_NAME}"
rm -f "/tmp/${SNAP_NAME}"
echo "==> Pruning snapshots older than 30 days..."
mc find "vps-minio/${BUCKET}" --older-than 30d --exec "mc rm {}" || true
/tmp/mc find "vps-minio/${BUCKET}" --older-than 30d --exec "/tmp/mc rm {}" || true
echo "==> Done: ${SNAP_NAME}"
---
@@ -91,10 +92,19 @@ spec:
spec:
serviceAccountName: argocd-hook-sa # already has kubectl exec rights in this namespace (see vault-init-job.yaml)
restartPolicy: Never
securityContext:
runAsNonRoot: true
runAsUser: 65534
seccompProfile:
type: RuntimeDefault
containers:
- name: raft-snapshot
image: alpine/k8s:1.32.13
command: ["/bin/bash", "/scripts/snapshot.sh"]
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
env:
- name: MINIO_ACCESS_KEY
valueFrom:
+1 -1
View File
@@ -30,7 +30,7 @@ set -euo pipefail
TOKEN_FILE="/etc/vps-dns-failover/cloudflare-token"
STATE_DIR="/var/lib/vps-dns-failover"
ZONE_NAME="kube.huskypup.net"
ZONE_NAME="huskypup.net" # Cloudflare zone is the parent domain - kube.huskypup.net is just a record within it, not its own zone
HOME_CHECK_HOST="home.kube.huskypup.net"
HOME_CHECK_PORT=443
FAILURE_THRESHOLD=3 # consecutive failed checks before flipping to the VPS