StackStorm/st2-docker

De root the applications and containers

Ouverte

#187 ouverte le 3 mars 2020

 (8 commentaires) (1 réaction) (0 personne assignée)Shell (169 forks)auto 404
bugenhancementhelp wantedsecurity

Métriques du dépôt

Stars
 (205 étoiles)
Métriques de merge PR
 (Aucune PR mergée en 30 j)

Description

Is your feature request related to a problem? Please describe. Since st2 uses a lot of root files, any underlying k8s configuration that blocks running containers as root (such as openshift) prevents the container from running at all because of all the configuration that is held in the roots (/etc, /root, /opt). It is also a massive security flaw to run the containers as root as any RCE can be used on the underlying host.

Describe the solution you'd like De-root the containers and applications. Contain it to it's own folderspace instead of using system folders for configuration.

Describe alternatives you've considered Not really any that I can think of for not running as root.

Guide contributeur