Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Feature] Run the PD, Store and Server images as a non-root user

Abierto
#3,211 2 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@SebastianGruza ya está trabajando en esto.

Desde el 20/9/2026.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
55/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
docker, helm, java, kubernetes

Línea de trabajo

Locate the Dockerfiles and entrypoints for the PD, Store and Server images, then inspect how their data, log and temporary directories are created and used. Build each image and verify the Java process runs as the fixed user without permission errors; document the PVC upgrade note and ensure the Helm chart's security contexts can adopt the new defaults.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

inactive

Feature Description (功能描述)

The published hugegraph/pd, hugegraph/store and hugegraph/server images all run their Java process as root: none of the three declares a USER, checked against the current latest image configs on Docker Hub (registry config blob, .config.User empty on all three, 2026-09-17).

Why it matters on Kubernetes:

  1. A namespace under the restricted Pod Security Standard rejects these pods outright (runAsNonRoot != true).
  2. The Helm chart in #3132 cannot set runAsNonRoot: true or readOnlyRootFilesystem: true as defaults; it documents this in its Limitations and ships the remaining hardening it can (allowPrivilegeEscalation: false, capabilities.drop: [ALL], seccompProfile: RuntimeDefault).
  3. Security scanners (kube-score, polaris, kubescape) flag every workload for it, which any adopter evaluating the chart sees on day one; the 2026-09-10 chart test campaign recorded it as a failing kubescape NSA control on both branches.

Proposal:

  • Create a fixed-UID user in each Dockerfile (the toolchain's Hubble image can follow the same pattern later) and chown the data and log directories to it.
  • Declare USER in the image and keep the entrypoints from writing outside the data, log and temp directories, so readOnlyRootFilesystem becomes possible as a follow-up.
  • Ship it in a minor release with an upgrade note: existing PVC data written as root needs a one-time chown, or an initContainer / fsGroup note in the chart.

The chart side is ready to adopt this the release it lands: podSecurityContext and securityContext are fully configurable per component today, so only the defaults would change.

Lenguaje dominante
Java
Estrellas
3.2k
Forks
641
Merge medio
2 d 4 h
PR fusionados (30 d)
31

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/hugegraph

Todos los issues de apache/hugegraph

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.