Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

API Reference: Securing Helm Chart Deployments

Helm Security Commands

Command Description
helm lint ./chart --strict Lint chart with strict mode
helm template release ./chart Render templates locally
helm verify chart.tgz Verify chart signature
helm package ./chart --sign --key <key> Package and sign
helm pull repo/chart --verify Pull with verification

Security Context Fields

Field Recommended Description
runAsNonRoot true Prevent root execution
readOnlyRootFilesystem true Immutable filesystem
allowPrivilegeEscalation false Block privilege escalation
capabilities.drop [ALL] Drop all Linux capabilities
seccompProfile.type RuntimeDefault Syscall filtering

Security Checks

Check Severity Risk
Privileged container High Full host access
hostNetwork enabled High Network namespace escape
hostPID enabled High Process namespace escape
:latest image tag Medium Non-reproducible builds
Missing resource limits Medium Resource exhaustion DoS
Missing readOnlyRootFilesystem Medium Writable filesystem

Template Scanning Tools

Tool Command
kubesec kubesec scan rendered.yaml
checkov checkov -f rendered.yaml --framework kubernetes
trivy trivy config rendered.yaml
kube-linter kube-linter lint rendered.yaml

Python Libraries

Library Version Purpose
subprocess stdlib Execute helm/kubesec CLI
re stdlib Pattern matching in rendered YAML
yaml PyYAML >=6.0 Parse YAML content
json stdlib Report generation

References