-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RHDEVDOCS-3306: Document running image build tasks as unprivileged builds #44733
Conversation
HarshCasper
commented
Apr 20, 2022
•
edited by abrennan89
edited by abrennan89
- JIRA ID: RHDEVDOCS-3306
- Applies for OCP 4.10+
- Aligned team: DevTools
- SME review:
- Peer Review: @rolfedh @abrennan89
- Docs Preview:
✅ Deploy Preview for osdocs ready!
To edit notification comments on pull requests, go to your Netlify site settings. |
8714c96
to
9d45f7d
Compare
cicd/pipelines/running-workload-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
cicd/pipelines/running-workload-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
8b73e1f
to
b33ca75
Compare
cicd/pipelines/running-workloads-and-buildah-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
cicd/pipelines/running-workloads-and-buildah-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
b33ca75
to
e90bf90
Compare
Please make sure to include elements/follow practices that are required by the mod docs standard and Jupiter.
|
e90bf90
to
e51a3c8
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added some review comments. Happy to take another look once a new preview has been added.
See https://docs.google.com/document/u/2/d/e/2PACX-1vRLKWEMHQ3DZroxZKfTu3XcrSdREr6D3oSSayBanEprXhkA2Ciyr2SQuDTYI4aIKUiOPPIQMHgjHeh8/pub#h.vrlifsbvvjd8 for instructions on adding a manual preview @HarshCasper
@HarshCasper please also add the affected versions to the description |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Added a review
cicd/pipelines/running-workloads-and-buildah-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
* Edit the `pipelines-scc` and modify the `runAsUser` and `seLinuxContext`. | ||
|
||
[source,yaml,subs="attributes+"] | ||
---- |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
same comment as per runAsUser
and seLinuxContext
- literals should always have a noun explaining them
638e40c
to
a91e16f
Compare
a91e16f
to
1f86c2b
Compare
The following output is displayed: | ||
+ | ||
[source,terminal] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Need SME input here.
1f86c2b
to
4fc4bea
Compare
4fc4bea
to
236de7c
Compare
... | ||
---- | ||
|
||
. Test it using the above `ConfigMap` object workspace along with a sample DockerFile and a sample taskrun. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Which sample?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
|
||
.Procedure | ||
|
||
* Edit the `pipelines-scc` and modify the `runAsUser` and `seLinuxContext`: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
IMHO it's safer to create a new SCC. This one is managed by operator so it could be removed or changed after updating OpenShift Pipelines.
cicd/pipelines/running-workloads-and-buildah-as-user-namespaces-on-openshift-pipelines.adoc
Outdated
Show resolved
Hide resolved
:_content-type: PROCEDURE | ||
|
||
[id="op-running-as-root-user-namespace_{context}"] | ||
= Running as root in a user namespace |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Based on Jake's comment below, how about:
= Running as root in a user namespace | |
= Running buildah as root in a user namespace |
Okay @jc-berger ?
236de7c
to
46b61a2
Compare
46b61a2
to
ac1e15e
Compare