OSVauco/tyr/memory_bank/completed.md

34 lines
1.2 KiB
Markdown

# Completed Tasks - TYR
- **Phase 1.1: Deploy step-ca**
- Status: **Complete**
- Notes: `step ca init` was successful and the `step-ca` systemd service is active.
- **Phase 1.2: Bootstrap SPIRE**
- Status: **Complete**
- Notes: `install_spire.sh` executed and daemons are running.
- **Phase 1.4: Binary Authorization**
- Status: **Complete**
- Notes: KMS key, attestor, and policy are created and active.
- **Task 2.1: Establish VPC-SC Perimeter**
- Status: **Complete**
- Notes: Created `tyr_perimeter` to restrict Cloud Run and Artifact Registry.
- **Task 2.2: Enable Private Google Access**
- Status: **Complete**
- Notes: Enabled Private Google Access on the default subnet in `us-central1`.
- **Task 2.3: Deploy Cloud Armor WAF**
- Status: **Complete**
- Notes: Created `tyr-armor-policy` with XSS, rate-limiting, and default-deny rules.
- **Task 2.4: Harden Ingress**
- Status: **Complete**
- Notes: Replaced default SSH rule with IAP-only rule and set Cloud Run ingress to internal.
- **Task 3.1: Draft Gatekeeper Policy**
- Status: **Complete**
- Notes: Wrote `container_security.yaml` with policies to disallow root and require resource limits.