Prerequisites:
- Kubernetes with NetworkPolicy and a
gvisor RuntimeClass or an approved
equivalent;
- customer PostgreSQL, Redis-compatible queue, object storage, and secret
backend;
- WorkOS connectivity or a contracted approved identity route;
- an immutable Veridical image digest and deployment-bound license;
- Vault KV v2 or GCP Secret Manager for provider credentials.
The chart uses non-root, read-only containers; drops all capabilities; forbids
privilege escalation, host paths, and Docker socket mounts; applies
default-deny NetworkPolicy; and pins the worker to the isolated pool.
For GKE Workload Identity, set the service-account annotation and
global.serviceAccount.automountToken: true. Vault-only installations keep the
token disabled. Last modified on July 28, 2026