StackStorm/st2-docker

De root the applications and containers

开放

#187 创建于 2020年3月3日

 (8 条评论) (1 个反应) (0 位负责人)Shell (169 个派生)auto 404
bugenhancementhelp wantedsecurity

仓库指标

星标
 (205 个星标)
PR 合并指标
 (PR 指标待抓取)

描述

Is your feature request related to a problem? Please describe. Since st2 uses a lot of root files, any underlying k8s configuration that blocks running containers as root (such as openshift) prevents the container from running at all because of all the configuration that is held in the roots (/etc, /root, /opt). It is also a massive security flaw to run the containers as root as any RCE can be used on the underlying host.

Describe the solution you'd like De-root the containers and applications. Contain it to it's own folderspace instead of using system folders for configuration.

Describe alternatives you've considered Not really any that I can think of for not running as root.

贡献者指南