mirror of
https://github.com/jmcorgan/fips.git
synced 2026-08-10 00:26:59 +00:00
Adds a complete Kubernetes sidecar setup under testing/k8s/ that runs FIPS as a sidecar container, injecting the mesh TUN interface (fips0) into any co-located app container via shared pod network namespace. - Multi-stage Dockerfile builds fips and fipsctl from source (debian trixie / rust slim-trixie), producing a minimal runtime image with iproute2, iptables, dnsmasq, and the two binaries - entrypoint.sh generates fips.yaml from environment variables, rewrites /etc/resolv.conf to route .fips DNS through dnsmasq, applies optional iptables isolation, clamps TCP MSS, then starts dnsmasq and execs the daemon - pod.yaml annotated example Pod manifest with Secret, sysctl tuning, readiness/liveness probes, and resource limits - scripts/build.sh convenience wrapper for docker build - testing/k8s/.dockerignore keeps the build context small - README.md usage guide covering quick start, isolation modes, env vars, multi-peer JSON config, troubleshooting