mirror of
https://github.com/luxfi/node.git
synced 2026-07-27 03:39:39 +00:00
Blocking (would cause production incidents): - env var prefix: LUX_* → LUXD_* (27 vars). Viper reads only LUXD_*; LUX_* silently ignored → node would start with default config on every env. - admin API enabled + sybil disabled defaults: explicit LUXD_API_ADMIN_ENABLED=false and LUXD_SYBIL_PROTECTION_ENABLED=true in base ConfigMap. - bootstrap peer config absent in new overlays: added LUXD_BOOTSTRAP_IPS / LUXD_BOOTSTRAP_IDS keys to base ConfigMap; overlays/operator populate per-env. Defense-in-depth additions: - ServiceAccount `luxd` with automountServiceAccountToken: false (no API access). - PodDisruptionBudget maxUnavailable=1 (works at 5 → 100 validator scales). - NetworkPolicy: ingress 9631/TCP from any (P2P), 9630/TCP cluster-only (HTTP), 9090/TCP monitoring-namespace only (metrics). - podAntiAffinity preferredDuringScheduling by hostname — spread across nodes. - updateStrategy: OnDelete — operator drains one pod at a time. - podManagementPolicy: Parallel — validators start in any order. Swarm verdict was NO-GO until these fixes. Addresses red critical #1 (admin API), #2 (sybil), high #4 (gateway bypass via direct LB), medium #7 (no NetworkPolicy/RBAC), and scientist blockers on env prefix + bootstrap.