v0.4.0GitHub

Enterprise

Kubernetes deployment

Standalone sidecar Helm chart and mutating admission auto-inject for NHIM runtime enforcement.

View as Markdown

Deploy Blekline NHIM runtime enforcement in your cluster — standalone sidecar (ClusterIP) or injected sidecar (mutating webhook).

Image

ghcr.io/blekline/sidecar:0.2.0-nhim

NHIM capabilities (Trust Vault, Lineage Firewall) require the NHIM image built from the private runtime engine. OSS ingress-proxy source is a contracts-only shell.

Topology A — Standalone sidecar

Platform team runs one sidecar Deployment; agent pods call it over ClusterIP.

helm upgrade --install sidecar packages/ingress-proxy/helm/blekline-ingress \
  -n blekline --create-namespace \
  -f deploy/k8s/sidecar/values-production.yaml

Agent env: BLEKLINE_SIDECAR_URL=http://<release>-blekline-ingress:8787

Requirements:

  • BLEKLINE_SIDECAR_AUTH — Bearer secret (required)
  • BLEKLINE_VAULT_MASTER_KEYTrust Vault encryption key
  • replicaCount: 1 + Recreate strategy when Trust Vault enabled
  • Never expose port 8787 on public Ingress

See Trust Vault sidecar and Lineage enforcement.

Topology B — Injected sidecar (auto-inject)

Mutating webhook adds blekline-sidecar to agent pods. Agents use http://127.0.0.1:8787.

Opt-in annotation:

metadata:
  annotations:
    blekline.com/inject-sidecar: enabled

Install:

helm upgrade --install blekline-admission deploy/k8s/admission/helm/blekline-admission \
  -n blekline --create-namespace

Requires cert-manager for webhook TLS (recommended) or manual CA bundle — see private operator pack deploy/k8s/README.md.

SPIFFE workload binding

Shipped v1: bind SPIFFE ID at tokenize; hydrate requires matching spiffeId or x-spiffe-id header.

VariablePurpose
BLEKLINE_SPIFFE_REQUIREDRequire SPIFFE ID on all hydrates
BLEKLINE_SPIFFE_ALLOWED_IDSComma-separated allowlist
BLEKLINE_SPIFFE_TRUST_DOMAINPrefix check, e.g. spiffe://prod.example

SPIRE Workload API JWT verification — roadmap.

Verification

kubectl -n blekline port-forward svc/sidecar-blekline-ingress 8787:8787
curl -s http://127.0.0.1:8787/health

Post-install Job: deploy/k8s/verify/[nhim](/docs/definitions/nhim)-smoke-job.yaml

Interactive demo: Runtime Simulator