Skip to content

Audit of custom GC repo for one-click-apps: action items #5

@IamJeffG

Description

@IamJeffG

Goal is to make sure this repo's CapRover one-click-app defns are generally useful to those deploying a Guardian Connector stack in organizations outside of ours.

My audit of caprover/one-click-apps identified, in no particular order:

  • superset-only.yml hard-codes the guardianconnector.net domain:
    • the superset admin user email
    • FRAME_ANCESTORS: "https://*.guardianconnector.net"
  • gcexplorer.yml uses :latest docker tag. This is convenient (pseudo-automatic upgrades, but which we don't control the timing of), however it may also lead to bloat of old Docker images cached on VMs - can lead to disk space issues on resource-constrained VMs
  • comapeo-cloud.yml and superset-only.yml point to images on a private container registery (guardiancr.azurecr.io). To use them requires either configuring private credentials via the CapRover dashboard, or to make them public. (which?)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions