gcloud-lab/apps/base/customer1
Hermes Agent d2f011956e fix: hermes-webui container start failure due to PodSecurity restricted policy
- Updated pod.spec.securityContext and all container/initContainer securityContext to be fully compliant with restricted:latest (runAsNonRoot: true, allowPrivilegeEscalation: false, runAsUser: 1000, capabilities drop ALL, seccomp RuntimeDefault, fsGroup)
- Changed initContainer from root chown to non-root mkdir/chmod relying on fsGroup (avoids PSA violation)
- Updated default model to grok-4.20-0309-reasoning (per xAI switch note)
- Added automountServiceAccountToken: false and imagePullPolicy for best practices (matches openclaw deployment pattern)
- hermes-webui now runs as non-root with WANTED_UID matching

This should resolve the container not starting. Leave PR open for review before merge.
2026-05-07 14:52:13 +00:00
..
db clean up and add routes to paas site 2026-04-28 03:31:52 +00:00
hermes-agent fix: hermes-webui container start failure due to PodSecurity restricted policy 2026-05-07 14:52:13 +00:00
hermes-db fix(hermes-db): reencrypt with correct SOPS recipient key 2026-05-02 22:14:09 +00:00
n8n clean up and add routes to paas site 2026-04-28 03:31:52 +00:00
news_bot Update kustomization.yaml 2026-04-25 09:59:24 -04:00
openclaw clean up and add routes to paas site 2026-04-28 03:31:52 +00:00
paaas-landing fix deoloyment 2026-05-05 00:51:36 +00:00
trade-dashboard clean up tsproxies 2026-05-04 14:55:37 +00:00
uncensored-bot clean up 2026-04-21 23:01:06 +00:00
http-route.yaml set up customer1 kustomization 2026-01-06 03:30:41 +00:00
kustomization.yaml fix kustomization 2026-04-28 03:40:54 +00:00
namespace.yaml remove pod security from namespace customer1 2026-02-09 22:44:07 +00:00
service.yaml set up customer1 kustomization 2026-01-06 03:30:41 +00:00