Skip to content

service-ca pod run as non-root#505

Closed
sallyom wants to merge 1 commit into
openshift:mainfrom
sallyom:service-ca-non-root
Closed

service-ca pod run as non-root#505
sallyom wants to merge 1 commit into
openshift:mainfrom
sallyom:service-ca-non-root

Conversation

@sallyom
Copy link
Copy Markdown
Contributor

@sallyom sallyom commented Dec 15, 2021

Signed-off-by: Sally O'Malley somalley@redhat.com

NOTE In order for service-ca to run with non-root, have to modify the signing-bundle and TLS crt,key volumes to be a configmap & secret, otherwise the non-root uid in the pod can't access the service-ca.crt, tls.crt, tls.key files it needs. Also, the OCP cluster-policy-controller must be running.

This PR depends on
#504 (service-ca volumes as CA configmap, TLS secret)
#478 (cluster-policy-controller)
Closes #

Signed-off-by: Sally O'Malley <somalley@redhat.com>
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented Dec 15, 2021

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
To complete the pull request process, please ask for approval from sallyom after the PR has been reviewed.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot requested review from fzdarsky and mangelajo December 15, 2021 03:03
@cooktheryan
Copy link
Copy Markdown
Contributor

/retest

1 similar comment
@cooktheryan
Copy link
Copy Markdown
Contributor

/retest

@sallyom
Copy link
Copy Markdown
Contributor Author

sallyom commented Dec 20, 2021

this will fail until #478 merges

@openshift-bot
Copy link
Copy Markdown

Issues go stale after 90d of inactivity.

Mark the issue as fresh by commenting /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.
Exclude this issue from closing by commenting /lifecycle frozen.

If this issue is safe to close now please do so with /close.

/lifecycle stale

@openshift-ci openshift-ci Bot added lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD. labels May 18, 2022
@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci Bot commented May 18, 2022

@sallyom: PR needs rebase.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@sallyom
Copy link
Copy Markdown
Contributor Author

sallyom commented Jun 2, 2022

closing, no longer needed

@sallyom sallyom closed this Jun 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. needs-rebase Indicates a PR cannot be merged because it has merge conflicts with HEAD.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants