Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Object store definition missing runAsUser and runAsGroup

Aperta
#1,145 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@gustabowill ci sta già lavorando.

Dal 5/10/2026.

  • #1146 di @gustabowill — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
25/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Ferma
Stack tecnologico
docker, go, kubernetes, yaml

Direzione di ricerca

Work is already in open PR #1146; do not start a duplicate. The failing manifests are the object-store and s3-client deployments under hack/object-store. Add runAsUser/runAsGroup 10001 for RustFS and 65534 (nobody) for the AWS CLI image so runAsNonRoot: true is valid. Done when those pods start without the kubelet runAsNonRoot errors quoted in the issue.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Commit ab992360e4ab656607fcafd6ba2096e930e9ffa8 replaced MinIO with RustFS, however the new object-store and s3-client deployment definitions in hack/object-store use runAsNonRoot: true without defining runAsUser.

As a result, the object-store deployment fails with the following error:

  Warning  Failed     2m46s (x234 over 52m)  kubelet            spec.containers{object-store}: Error: container has runAsNonRoot and image has non-numeric user (rustfs), cannot verify user is non-root (pod: "object-store-8cc85b8b9-4x8zw_default(69cd378e-266e-4732-8ee2-a7af55b44032)", container: object-store)

And the s3-client deployment with:

  Warning  Failed     88s (x235 over 51m)  kubelet            spec.containers{s3-client}: Error: container has runAsNonRoot and image will run as root (pod: "s3-client-648c964d57-qw8ww_default(935a202f-dcc3-4432-b896-dc5992566a87)", container: s3-client)

The RustFS image has the user and group IDs as 10001:

$ docker run --rm --entrypoint sh \
  docker.io/rustfs/rustfs@sha256:bffcab0c9d647aab0055d1c69d340b202d0909966b385932d4ead1aeb7602858 \
  -c 'id rustfs; grep rustfs /etc/passwd /etc/group'
uid=10001(rustfs) gid=10001(rustfs) groups=10001(rustfs)
/etc/passwd:rustfs:x:10001:10001::/home/rustfs:/sbin/nologin
/etc/group:rustfs:x:10001:

The AWS CLI image has no dedicated user, but it ships nobody, which we can use:

$ docker run --rm --entrypoint sh \
  docker.io/amazon/aws-cli@sha256:337494c2047176fe9abcf45a5d1eaf1c2c62cae40953284fb1143b5c6170f065 \
  -c 'grep nobody /etc/passwd /etc/group'
/etc/passwd:nobody:x:65534:65534:Kernel Overflow User:/:/sbin/nologin
/etc/group:nobody:x:65534:

We should set the respective runAsUser and runAsGroup on both YAML definitions.

Lingua principale
Go
Stelle
198
Fork
81
Merge medio
4g 13h
PR unite (30g)
19

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di cloudnative-pg/plugin-barman-cloud

Tutte le issue di cloudnative-pg/plugin-barman-cloud

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.