Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[buildah] Remove privileged: true by adding SETFCAP cap #1298

Open
jsalatiel opened this issue Aug 21, 2024 · 0 comments
Open

[buildah] Remove privileged: true by adding SETFCAP cap #1298

jsalatiel opened this issue Aug 21, 2024 · 0 comments

Comments

@jsalatiel
Copy link

The buildah task has privileged: true set in its pod securityContext

That can be replaced by

securityContext:
  capabilities:
     add:
     - SETFCAP

and the build will work without needing privileged which sometimes is not allowed in the cluster.

Tested in k8s 1.30 running crio 1.30

@jsalatiel jsalatiel changed the title [buildah] Replace privileged: true by adding SETFCAP cap [buildah] Remove privileged: true by adding SETFCAP cap Aug 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant