Skip to content

Commit

Permalink
[stable/spinnaker] Relax PSP (helm#22867)
Browse files Browse the repository at this point in the history
Some processes need to change files from different users (deck for
instance).
If the pod is run as non root, deck does not start:

**********************
cp: cannot create regular file 'spinnaker.conf': Permission denied
sed: can't read spinnaker.conf: No such file or directory
sed: can't read spinnaker.conf: No such file or directory
sed: can't read spinnaker.conf: No such file or directory
mv: cannot stat 'spinnaker.conf': No such file or directory
ERROR: Site spinnaker does not exist!
Could not remove /etc/apache2/sites-enabled/000-default.conf: Permission denied
cp: cannot create regular file 'ports.conf': Permission denied
sed: can't read ports.conf: No such file or directory
sed: can't read ports.conf: No such file or directory
mv: cannot stat 'ports.conf': No such file or directory
cp: cannot create regular file 'passphrase': Permission denied
sed: can't read passphrase: No such file or directory
chmod: cannot access 'passphrase': No such file or directory
mv: cannot stat 'passphrase': No such file or directory
cp: cannot create regular file '/opt/deck/html/settings.js': Permission denied
chown: changing ownership of '/var/lock/apache2.ZWzj1uONRl': Operation not permitted
**********************

Relaxing the PSP to allow this.

Signed-off-by: Fabrice Rabaute <[email protected]>
Signed-off-by: camelusluo <[email protected]>
  • Loading branch information
jfrabaute authored and camelusluo committed Jul 6, 2020
1 parent e586fca commit d3554db
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 2 deletions.
2 changes: 1 addition & 1 deletion stable/spinnaker/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
apiVersion: v1
description: Open source, multi-cloud continuous delivery platform for releasing software changes with high velocity and confidence.
name: spinnaker
version: 2.0.0-rc6
version: 2.0.0-rc7
appVersion: 1.16.2
home: http://spinnaker.io/
sources:
Expand Down
2 changes: 1 addition & 1 deletion stable/spinnaker/templates/rbac/psp-halyard.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ spec:
hostIPC: false
hostPID: false
runAsUser:
rule: 'MustRunAsNonRoot'
rule: 'RunAsAny'
seLinux:
rule: 'RunAsAny'
supplementalGroups:
Expand Down

0 comments on commit d3554db

Please sign in to comment.