diff --git a/charts/terdut-server/templates/bootstrap-job.yaml b/charts/terdut-server/templates/bootstrap-job.yaml index e2be2ad..b3adc2b 100644 --- a/charts/terdut-server/templates/bootstrap-job.yaml +++ b/charts/terdut-server/templates/bootstrap-job.yaml @@ -23,13 +23,23 @@ spec: serviceAccountName: {{ include "terdut-server.fullname" . }}-bootstrap containers: - name: bootstrap - image: alpine:3 + # alpine/curl, not alpine:3 + `apk add curl`. Installing the binary at run time + # writes it into the container's writable upper layer, which is exactly the + # signature Falco's `Drop and execute new binary in container` (MITRE TA0003) + # exists to catch -- this hook emitted two Critical events on every single + # upgrade. See Ryuvia/charts#100. It also made `helm upgrade` depend on the + # Alpine CDN answering, since this runs as a post-upgrade hook and a failed + # hook fails the release. + # + # Still a full Alpine underneath, so sh, cat, sleep, grep, cut, head and tail + # are all present (verified in-cluster 2026-09-04). The image declares + # ENTRYPOINT ["/entrypoint.sh"], which `command:` below overrides -- do not + # change `command:` to `args:`. + image: alpine/curl:8.21.0@sha256:a1c44bab54d88e18ea9a6a4ecefab7f2d230b968567b78960fcaff8d51b7f067 command: - /bin/sh - -c - | - apk add --no-cache curl > /dev/null 2>&1 - SERVICE_URL="http://{{ include "terdut-server.fullname" . }}:{{ .Values.service.port }}" SECRET_NAME="{{ include "terdut-server.bootstrapSecretName" . }}" K8S_API="https://kubernetes.default.svc"