# Runtime security

- Run workloads as a non-root identity supplied by applicable platform policy or explicit deployment values; do not assume that omitting image USER ensures non-root execution. Use a read-only root filesystem with explicit writable mounts. Keep runtime identity and Pod security configurable with unset chart defaults; follow `building/general` for image permissions and `deploying/general` for admission behavior. If no applicable policy provides seccomp, supply `seccompProfile.type: RuntimeDefault` at Pod level in deployment values.
- Keep credentials out of source control, images and logs. Use the platform’s secret generator, secret store or other discovered provisioning mechanism; commit declarations, never generated values. Consume Kubernetes Secrets through explicit references or mounted files. Locally, use untracked configuration or Docker secrets.
- Make rotation fast and repeatable without rebuilding images. Give separate component relationships their own credentials; reuse operator-generated credentials when the operator owns authentication. Provision replacements, update all consumers through their supported reload or rollout mechanism, verify access, then revoke old credentials. Allow an overlap where supported for routine rotation; compromised credentials may require immediate revocation. Keep the rotation procedure documented and verify it works. Network trust requirements belong to `deploying/networking`.
- Provision OIDC registrations through the selected identity service, following `developing/architecture` and the dependency ownership rules in `deploying/storage`. Align issuer, audience and HTTPS redirect URIs. Keep confidential client credentials on the server.
- Provision session-signing secrets once and share them across application replicas. Rotate deliberately; do not regenerate them on every deployment.
