Skip to content

Remove privileged mode requirement#101

Merged
siegfriedweber merged 11 commits intomainfrom
remove-privileged-mode
Sep 7, 2023
Merged

Remove privileged mode requirement#101
siegfriedweber merged 11 commits intomainfrom
remove-privileged-mode

Conversation

@siegfriedweber
Copy link
Copy Markdown
Member

@siegfriedweber siegfriedweber commented Aug 31, 2023

Description

Remove the requirement for privileged mode.

The SELinux options still have to be quite privileged to allow the listener-operator to write into the volumes in other namespaces.

Closes #70

Definition of Done Checklist

  • Not all of these items are applicable to all PRs, the author should update this template to only leave the boxes in that are relevant
  • Please make sure all these things are done and tick the boxes
# Author
- [x] Changes are OpenShift compatible
- [x] CRD changes approved
- [x] Helm chart can be installed and deployed operator works
- [x] Integration tests passed (for non trivial changes)
# Reviewer
- [x] Code contains useful comments
- [ ] (Integration-)Test cases added
- [ ] Documentation added or updated
- [x] Changelog updated
- [x] Cargo.toml only contains references to git tags (not specific commits or branches)
# Acceptance
- [ ] Feature Tracker has been updated
- [ ] Proper release label has been added

@siegfriedweber siegfriedweber self-assigned this Aug 31, 2023
Copy link
Copy Markdown
Member

@razvan razvan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

First installation attempt failed on OpenShift 4.12:

helm upgrade listener-operator listener-operator --install --namespace stackable-operators --version 0.0.0-pr101 --wait  --devel --repo https://repo.stackable.tech/repository/helm-test

Event message:

Error creating: pods "listener-operator-controller-deployment-6df677f8df-" is forbidden: unable to validate against any security context constraint: [provider "anyuid": Forbidden: not usable by user or serviceaccount, provider "pipelines-scc": Forbidden: not usable by user or serviceaccount, provider "pipelines-custom-scc": Forbidden: not usable by user or serviceaccount, provider restricted-v2: .containers[0].runAsUser: Invalid value: 0: must be in the ranges: [1000710000, 1000719999], provider restricted: .containers[0].runAsUser: Invalid value: 0: must be in the ranges: [1000710000, 1000719999], provider "nonroot-v2": Forbidden: not usable by user or serviceaccount, provider "nonroot": Forbidden: not usable by user or serviceaccount, provider "hostmount-anyuid": Forbidden: not usable by user or serviceaccount, provider "zookeeper-scc": Forbidden: not usable by user or serviceaccount, provider "hbase-scc": Forbidden: not usable by user or serviceaccount, provider "hdfs-scc": Forbidden: not usable by user or serviceaccount, provider "machine-api-termination-handler": Forbidden: not usable by user or serviceaccount, provider "hostnetwork-v2": Forbidden: not usable by user or serviceaccount, provider "hostnetwork": Forbidden: not usable by user or serviceaccount, provider "hostaccess": Forbidden: not usable by user or serviceaccount, provider "node-exporter": Forbidden: not usable by user or serviceaccount, provider "privileged": Forbidden: not usable by user or serviceaccount, provider "privileged-genevalogging": Forbidden: not usable by user or serviceaccount]

@razvan
Copy link
Copy Markdown
Member

razvan commented Aug 31, 2023

Sorry for the formatting. The relevant part is this:

.containers[0].runAsUser: Invalid value: 0: must be in the ranges: [1000710000, 1000719999]

@siegfriedweber siegfriedweber requested a review from razvan August 31, 2023 11:18
@siegfriedweber
Copy link
Copy Markdown
Member Author

@siegfriedweber siegfriedweber added this pull request to the merge queue Sep 7, 2023
Merged via the queue into main with commit bf3ee2b Sep 7, 2023
@bors bors bot deleted the remove-privileged-mode branch September 7, 2023 16:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

Remove privileged mode requirement

4 participants