Merge pull request 'Remove INSTALLATION_POLICY.md and link to org wiki' (#85) from gandalf/remove-installation-policy into main
CI / ci (push) Successful in 51s
CI / ci (push) Successful in 51s
Merge PR #85: Remove INSTALLATION_POLICY.md and link to org wiki
This commit was merged in pull request #85.
This commit is contained in:
@@ -1,24 +0,0 @@
|
|||||||
# Installation Policy
|
|
||||||
|
|
||||||
## Approved Installation Method
|
|
||||||
|
|
||||||
**The ONLY approved method for installing this plugin is via [Artifact Hub](https://artifacthub.io/) using the Headlamp plugin installer.**
|
|
||||||
|
|
||||||
No other installation method is acceptable. This includes but is not limited to:
|
|
||||||
|
|
||||||
- Direct installation from GitHub release assets
|
|
||||||
- Manual npm pack / tarball extraction
|
|
||||||
- initContainer workarounds that bypass Artifact Hub
|
|
||||||
- Direct file copy or sidecar injection
|
|
||||||
|
|
||||||
## Enforcement
|
|
||||||
|
|
||||||
All deployment configurations, CI/CD pipelines, and documentation MUST reference Artifact Hub as the sole plugin distribution channel. Any pull request that introduces an alternative installation method will be rejected.
|
|
||||||
|
|
||||||
## Rationale
|
|
||||||
|
|
||||||
Artifact Hub provides verified checksums, consistent versioning, and a standard discovery mechanism for the CNCF ecosystem. Bypassing it introduces security and integrity risks.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
*This policy is set by the CTO and approved by the CEO of Privileged Escalation.*
|
|
||||||
@@ -50,6 +50,10 @@ Rook-Ceph must be deployed in the `rook-ceph` namespace with standard labels. Th
|
|||||||
|
|
||||||
Browse the Headlamp Plugin Manager (Settings → Plugins → Catalog) and install **headlamp-rook-plugin** directly.
|
Browse the Headlamp Plugin Manager (Settings → Plugins → Catalog) and install **headlamp-rook-plugin** directly.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
> See [Plugin Installation Policy](https://git.farh.net/privilegedescalation/privilegedescalation.com/wiki/Plugin-Installation-Policy) for approved installation methods.
|
||||||
|
|
||||||
## RBAC & Security Setup
|
## RBAC & Security Setup
|
||||||
|
|
||||||
The plugin reads Rook-Ceph CRDs and Kubernetes resources. Your Headlamp service account needs:
|
The plugin reads Rook-Ceph CRDs and Kubernetes resources. Your Headlamp service account needs:
|
||||||
|
|||||||
Reference in New Issue
Block a user