fix(deployment): run plugin container as the reposilite user
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 27s
Generate README / generate-parameters (push) Successful in 42s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 42s
Release / publish-chart (push) Successful in 1m16s
Helm / helm-lint (push) Successful in 8s
Helm / helm-unittest (push) Successful in 27s
Generate README / generate-parameters (push) Successful in 42s
Markdown linter / markdown-link-checker (push) Successful in 38s
Markdown linter / markdown-lint (push) Successful in 42s
Release / publish-chart (push) Successful in 1m16s
The reposilite entrypoint chowns /app to 977:977 whenever it starts as root. The plugin container downloaded the jar as its own image user (101), so after the first start the file was owned by 977:977 with mode 0644. Since the plugins emptyDir survives a container restart within the same pod, a restarted plugin container could no longer overwrite the existing jar and aborted with "Permission denied", which left the pod in a permanent Init:CrashLoopBackOff until the pod itself was recreated. Run the plugin container as 977:977 by default and expose the security context as deployment.pluginContainer.securityContext, so it can be aligned when PUID/PGID are overridden. Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -71,7 +71,11 @@
|
||||
{{- if eq (include "reposilite.plugins.prometheus.enabled" $) "true" }}
|
||||
{{- $fileName := splitList "/" (tpl .Values.config.plugins.prometheus.url $) | last }}
|
||||
{{- $individualArgs := concat $pluginContainerArgs (list "--output" $fileName (tpl .Values.config.plugins.prometheus.url $)) }}
|
||||
{{- $initContainers = concat $initContainers (list (dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts)) }}
|
||||
{{- $pluginContainer := dict "args" $individualArgs "name" "download-prometheus-plugin" "image" $pluginContainerImage "volumeMounts" $pluginContainerVolumeMounts }}
|
||||
{{- with .Values.deployment.pluginContainer.securityContext }}
|
||||
{{- $_ := set $pluginContainer "securityContext" . }}
|
||||
{{- end }}
|
||||
{{- $initContainers = concat $initContainers (list $pluginContainer) }}
|
||||
{{- end }}
|
||||
|
||||
{{ toYaml (dict "initContainers" $initContainers) }}
|
||||
|
||||
Reference in New Issue
Block a user