Skip to main content
Prerequisites:
  • Kubernetes with NetworkPolicy and a gvisor RuntimeClass or an approved equivalent;
  • customer PostgreSQL, Redis-compatible queue, object storage, and secret backend;
  • WorkOS connectivity or a contracted approved identity route;
  • an immutable Veridical image digest and deployment-bound license;
  • Vault KV v2 or GCP Secret Manager for provider credentials.
The chart uses non-root, read-only containers; drops all capabilities; forbids privilege escalation, host paths, and Docker socket mounts; applies default-deny NetworkPolicy; and pins the worker to the isolated pool. For GKE Workload Identity, set the service-account annotation and global.serviceAccount.automountToken: true. Vault-only installations keep the token disabled.
Last modified on July 28, 2026