Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[buildah] Remove privileged: true by adding SETFCAP cap #1298

Open
jsalatiel opened this issue Aug 21, 2024 · 0 comments
Open

[buildah] Remove privileged: true by adding SETFCAP cap #1298

jsalatiel opened this issue Aug 21, 2024 · 0 comments

Comments

@jsalatiel
Copy link

The buildah task has privileged: true set in its pod securityContext

That can be replaced by

securityContext:
  capabilities:
     add:
     - SETFCAP

and the build will work without needing privileged which sometimes is not allowed in the cluster.

Tested in k8s 1.30 running crio 1.30

@jsalatiel jsalatiel changed the title [buildah] Replace privileged: true by adding SETFCAP cap [buildah] Remove privileged: true by adding SETFCAP cap Aug 21, 2024
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant