ragleap-ops · release notes
2026-10-02 · ragleap-ops-v0.4.0
ragleap-ops v0.4.0
Added
- Zero-permission ServiceAccounts in the Helm chart for
db, app, voice and neo4j (serviceAccount.create, default true), with no API token mounted.
- README section "Helm chart and hardening", including the upgrade note.
Included from earlier unreleased work
readOnlyRootFilesystem for db, app and voice (deliberately not neo4j), and RUNBOOK.md with four incident playbooks, each drilled against a deliberately broken cluster.
Upgrading from 0.3.0
- If ServiceAccounts already exist from the raw
k8s/ manifests, install with --set serviceAccount.create=false, or delete them first.
Known limitations
- Only the
db pod was checked live for the ServiceAccount change; the app and voice pods could not start in the test namespace (missing pull secret).
Release notes mirrored from GitHub Releases.