Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[security] UI pod is run with full privileges #500

Open
eero-t opened this issue Oct 25, 2024 · 0 comments
Open

[security] UI pod is run with full privileges #500

eero-t opened this issue Oct 25, 2024 · 0 comments
Assignees
Labels

Comments

@eero-t
Copy link
Contributor

eero-t commented Oct 25, 2024

UI is the only pod running with full privileges although securing it would be most important due to it being exposed outside the cluster.

opea-project/GenAIExamples#517 claims that UI needs to be run as root, but that's not an excuse to avoid tightening rest of the privileges: https://github.com/opea-project/GenAIInfra/blob/main/helm-charts/common/ui/values.yaml#L25

@joshuayao joshuayao added the helm label Oct 30, 2024
@lianhao lianhao modified the milestone: v1.2 Nov 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants