Claude Config API (v0.6): - Add CRUD endpoints for commands, skills, and agents - Commands/skills/agents stored in /workspace/.claude/ (per-project, in git) - Credentials shared via PVC at /root/.claude/ (shared across pods) - Use base64 encoding for file writes (prevents shell injection) - Add content size limits (1MB max) Security Hardening: - Add sanitize package for command/prompt validation - Add rate limiting middleware (token bucket algorithm) - Add concurrent command limiting - Add input sanitization to all command handlers - Gitignore secrets.yaml and credentials.yaml - Add *.example templates for secrets Testing Infrastructure: - Add testutil package with mocks and fixtures - Add unit tests for auth package (63% coverage) - Add unit tests for executor (47% coverage) - Add handler integration tests (40% coverage) - Add 100% coverage for sanitize, cmdlimit packages - Add 96% coverage for ratelimit package Infrastructure: - Shared Claude credentials PVC (ReadWriteMany) - Reduced workspace PVC size from 20Gi to 5Gi - Add init container cleanup before git clone - Document Longhorn RWX requirements Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
30 lines
1010 B
YAML
30 lines
1010 B
YAML
# Shared Claude credentials PVC
|
|
# v0.6 - All claudebox pods share this for auth
|
|
# Commands/skills/agents live in /workspace/.claude (per-project, in git)
|
|
#
|
|
# IMPORTANT: ReadWriteMany (RWX) requires Longhorn with NFS enabled.
|
|
# Verify with: kubectl get settings -n longhorn-system rwx-volume-fast-failover
|
|
# If RWX is not available, either:
|
|
# 1. Enable Longhorn NFS: kubectl apply -f longhorn-nfs-provisioner.yaml
|
|
# 2. Or use separate PVCs per pod (revert to per-project claude-config PVCs)
|
|
#
|
|
# RWX is needed because multiple claudebox pods mount this simultaneously
|
|
# to share Claude authentication credentials.
|
|
|
|
apiVersion: v1
|
|
kind: PersistentVolumeClaim
|
|
metadata:
|
|
name: claudebox-shared-claude-config
|
|
namespace: rdev
|
|
labels:
|
|
app.kubernetes.io/name: claudebox
|
|
app.kubernetes.io/part-of: rdev
|
|
rdev.orchard9.ai/type: shared-config
|
|
spec:
|
|
accessModes:
|
|
- ReadWriteMany # Multiple pods can mount simultaneously
|
|
storageClassName: longhorn
|
|
resources:
|
|
requests:
|
|
storage: 1Gi
|