Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use more restrictive defaultMode for secret mounts #413

Merged
merged 1 commit into from Nov 18, 2020

Conversation

JAORMX
Copy link
Contributor

@JAORMX JAORMX commented Nov 11, 2020

This uses a more restrictive file mode for the mounted secrets for the
openshift-apiserver container. By the default, the resulting mode of the
files will be 0644, which is not ideal. So let's use 0600 which ensures
that the files are only accessible by root.

This uses a more restrictive file mode for the mounted secrets for the
openshift-apiserver container. By the default, the resulting mode of the
files will be 0644, which is not ideal. So let's use 0600 which ensures
that the files are only accessible by root.
@JAORMX
Copy link
Contributor Author

JAORMX commented Nov 11, 2020

/retest

@JAORMX
Copy link
Contributor Author

JAORMX commented Nov 11, 2020

/test e2e-aws

2 similar comments
@JAORMX
Copy link
Contributor Author

JAORMX commented Nov 12, 2020

/test e2e-aws

@JAORMX
Copy link
Contributor Author

JAORMX commented Nov 18, 2020

/test e2e-aws

@sttts
Copy link
Contributor

sttts commented Nov 18, 2020

/lgtm
/approve

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Nov 18, 2020
@openshift-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: JAORMX, sttts

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 18, 2020
@openshift-merge-robot openshift-merge-robot merged commit 3869669 into openshift:master Nov 18, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants