Skip to content

fix: allow non-root canary runtime files on its emptyDir - #4

Closed
r33drichards wants to merge 1 commit into
masterfrom
codex/inspircd-canary-volume-permissions
Closed

r33drichards wants to merge 1 commit into
masterfrom
codex/inspircd-canary-volume-permissions

Conversation

@r33drichards

Copy link
Copy Markdown

Source preflight identified that InspIRCd::WritePID opens /irc/inspircd.pid and exits on failure, while the canary runs UID/GID1000 with an emptyDir and no fsGroup. Add only pod fsGroup1000 so the existing runtime emptyDir is writable by that user. Preserve non-root UID/GID, read-only rootfs, dropped capabilities, seccomp, localhost-only bind, immutable image and no token. This is a source-identified startup risk, not yet an observed live error because sandbox creation is separately blocked by shim options. No privileges/hostPath/RBAC/public ingress. Server dry-run and diff check pass. Cloud source remains pinned to previous commit until exact-head CI/review plus separate reviewed pin update; current HTTP healthy.

@r33drichards

Copy link
Copy Markdown
Author

Superseded by the user-requested native Docker/ECR pivot after the WASM owner stood down. This unapplied fsGroup-only canary change is not being merged. Preserve the branch and public repository for audit; runtime removal is coordinated separately through cloud GitOps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant