Report suspected security vulnerabilities privately to the maintainers. Use GitHub private vulnerability reporting if enabled for this repository; otherwise contact a maintainer through a private channel. Include affected revision, reproduction, impact, and proposed mitigation. Do not post live credentials or sensitive cluster details publicly.
This document describes mechanisms visible in source, not an independent certification or a current vulnerability scan. Historical audit counts and zero-CVE claims are not evidence of present security.
Production deployment is owned by pulse-operator. Its OAuth proxy authenticates users and supplies identity/access-token headers to generated nginx configuration. Direct Kubernetes UI operations use the forwarded user's token; server-side Kubernetes RBAC decides permissions. The browser's SelfSubjectAccessReview controls are convenience controls, not authorization enforcement.
Agent calls use a separate shared token injected by the server proxy. The browser does not need to know it. Some agent endpoints additionally require an administrator identity. Interactive chat writes, direct UI writes, and autonomous monitor actions have different execution paths: autonomous backend work uses backend service-account credentials. The UI service account and agent service account are distinct; do not assume that every operation in the full stack has the UI service account's permissions or is attributed to the human user.
The authoritative deployment grants/security contexts/network policies are in the operator source and deployed resources. Verify them for the revision and configuration actually installed; this UI repository does not maintain production manifests.
Browser trust preferences are stored per hostname. They are not a server-side authorization boundary, and selecting a lower local trust does not necessarily lower backend monitor policy. Mission Control reports the backend's effective level when available. Category selection currently does not establish a restrictive backend allowlist, and Bounded chat requires approval when the backend supplies no verified category. Review these behaviors before enabling autonomous actions.
Observe blocks the reviewed chat confirmation paths, including keyboard approval. Deployment revision rollback uses JSON Patch with a resourceVersion test and replacement of the template. These protections do not establish that every other mutation path has equivalent preconditions or trust checks. Live cluster switching, concurrent updates, and partial failures need explicit validation.
Dockerfile uses the Red Hat UBI nginx base and packages built dist/. The base currently uses a moving latest tag; builds must be scanned and pinned by the release process to establish reproducible security. Dockerfile.helm-runner builds a separate product-feature image. Operator image defaults/overrides, including OAuth proxy and backend dependencies, belong to the operator repository.
Production nginx security headers, upstream TLS verification, Route termination, pod security contexts, resource limits, and NetworkPolicy are generated by the operator. Inspect the deployed objects rather than relying on old numerical limits or a claim that all images come from one registry. TLS trust roots for the Kubernetes API and OpenShift monitoring services can differ.
Source contains CRLF stripping in impersonation header values (engine/query.ts), path segment sanitization in API-path helpers (engine/gvr.ts), PromQL sanitization for selected query construction, and protocol/address validation for Helm repository fetching (src/dev/helmRepoProxy.ts). These helpers cover their callers; they are not proof that every input/path is validated. React escaping and production CSP reduce common injection paths but do not replace review of generated components, links, logs, or YAML data.
Impersonation is privileged Kubernetes functionality. The UI banner does not prove all backend or monitoring requests share that identity, and group header handling must be tested against the actual proxy/API server. Agent autonomy retains its own configured authority.
The dev server proxies using developer credentials. Keep it and oc proxy private; do not treat development proxy authentication/TLS settings as production hardening. rspack.config.ts reads exported environment variables. Never commit tokens, print them in test output, or share screenshots containing them. E2E tests may perform writes: use a disposable test environment.
Use the pinned pnpm version/lockfile, run pnpm audit, and scan the built container image for the exact digest being released. Record scan date, tool/database version, digest and unresolved findings. A historical clean scan is not a guarantee for a later build.
pnpm verify runs types, lint, tests, and build. Optional scripts/install-hooks.sh installs type-check/tests before commits; no pre-push or post-write security scan is installed by that script. CI jobs and release workflows are in .github/workflows/; verify their current run results separately.
Before using a new release, verify OAuth login/token expiry, unauthorized/missing-identity failures, per-user RBAC for direct writes, admin restrictions for agent mutation endpoints, autonomous policy/cooldowns, network isolation, and backup/restore against an authorized test cluster. Rotate Secrets using the operator's coordinated procedure; deleting database credential Secrets does not rotate the password stored inside PostgreSQL.