Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Object store definition missing runAsUser and runAsGroup

Đang mở
#1,145 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@gustabowill đang làm issue này rồi.

Từ ngày 5/10/2026.

  • #1146 của @gustabowill — đang mở

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
25/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
docker, go, kubernetes, yaml
Lĩnh vực
cloud, devops, infrastructure

Hướng nghiên cứu

Work is already in open PR #1146; do not start a duplicate. The failing manifests are the object-store and s3-client deployments under hack/object-store. Add runAsUser/runAsGroup 10001 for RustFS and 65534 (nobody) for the AWS CLI image so runAsNonRoot: true is valid. Done when those pods start without the kubelet runAsNonRoot errors quoted in the issue.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Commit ab992360e4ab656607fcafd6ba2096e930e9ffa8 replaced MinIO with RustFS, however the new object-store and s3-client deployment definitions in hack/object-store use runAsNonRoot: true without defining runAsUser.

As a result, the object-store deployment fails with the following error:

  Warning  Failed     2m46s (x234 over 52m)  kubelet            spec.containers{object-store}: Error: container has runAsNonRoot and image has non-numeric user (rustfs), cannot verify user is non-root (pod: "object-store-8cc85b8b9-4x8zw_default(69cd378e-266e-4732-8ee2-a7af55b44032)", container: object-store)

And the s3-client deployment with:

  Warning  Failed     88s (x235 over 51m)  kubelet            spec.containers{s3-client}: Error: container has runAsNonRoot and image will run as root (pod: "s3-client-648c964d57-qw8ww_default(935a202f-dcc3-4432-b896-dc5992566a87)", container: s3-client)

The RustFS image has the user and group IDs as 10001:

$ docker run --rm --entrypoint sh \
  docker.io/rustfs/rustfs@sha256:bffcab0c9d647aab0055d1c69d340b202d0909966b385932d4ead1aeb7602858 \
  -c 'id rustfs; grep rustfs /etc/passwd /etc/group'
uid=10001(rustfs) gid=10001(rustfs) groups=10001(rustfs)
/etc/passwd:rustfs:x:10001:10001::/home/rustfs:/sbin/nologin
/etc/group:rustfs:x:10001:

The AWS CLI image has no dedicated user, but it ships nobody, which we can use:

$ docker run --rm --entrypoint sh \
  docker.io/amazon/aws-cli@sha256:337494c2047176fe9abcf45a5d1eaf1c2c62cae40953284fb1143b5c6170f065 \
  -c 'grep nobody /etc/passwd /etc/group'
/etc/passwd:nobody:x:65534:65534:Kernel Overflow User:/:/sbin/nologin
/etc/group:nobody:x:65534:

We should set the respective runAsUser and runAsGroup on both YAML definitions.

Ngôn ngữ chính
Go
Star
196
Fork
76
Merge trung bình
4 ngày 13 giờ
Pull request đã merge (30 ngày)
19

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của cloudnative-pg/plugin-barman-cloud

Tất cả issue của cloudnative-pg/plugin-barman-cloud

Issue tương tự

Thêm issue về Go

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.