Sitelet https://github.com/OctopusDeploy/docs/pull/3490
Skip to content

Add docs for the hardened Octopus Server Linux Container - #3490

Draft
hnrkndrssn wants to merge 2 commits into
mainfrom
henrik/feat/hardened-server-container-docs
Draft

hnrkndrssn wants to merge 2 commits into
mainfrom
henrik/feat/hardened-server-container-docs

Conversation

@hnrkndrssn

@hnrkndrssn hnrkndrssn commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Background

Adds documentation for the hardened Octopus Server Linux Container being built in OctopusDeploy/OctopusDeploy#47150.

Fixes SI-217

Changes

  • New page installation/octopus-server-linux-container/hardened-image.md covering:
    • What the hardened image is and who it's for
    • Security update expectations: we pick up OpenSSL/base image changes, even when they break older Tentacles, SSH targets, or clients (the main ask in SI-217)
    • Standard vs hardened comparison
    • Running as a non-root or arbitrary UID (Docker, Kubernetes, OpenShift), volume permissions, and a read-only root filesystem
    • Environment variables, ports, and volumes
    • The container-healthcheck command and Kubernetes probe examples
    • Unsupported features: built-in worker, Script Console on the server, execution containers on the built-in worker, Let's Encrypt
    • Switching between the standard and hardened images, upgrading, and troubleshooting without a shell
  • Links the new page from the Linux container index page
  • Adds SGID to the spelling dictionary

Open questions before publishing

  • Confirm the public image tag (<version>-hardened is a placeholder), and whether there's a latest-hardened
  • Confirm a read-only root filesystem is supported
  • Confirm Kubernetes fsGroup: 0 / OpenShift restricted SCC guidance
  • Confirm the built-in worker stays off after switching back to the standard image
  • Check the descriptions for the /etc/octopus and /Octopus/.octopus/OctopusServer/Server volumes
  • Decide whether we need a release version or early access callout

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hnrkndrssn hnrkndrssn self-assigned this Oct 1, 2026
@team-marketing-branch-protections

Copy link
Copy Markdown

Pull request environment is available at https://stoctodocspr3490.z22.web.core.windows.net/.

You can view the ephemeral environment status in Octopus Deploy.

This environment will be automatically deprovisioned when the pull request is closed, or after 7 days of inactivity.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants