Skip to content

Ensure we set sticky bit on mounted tmp folders #194

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

oliverguenther
Copy link
Member

@oliverguenther oliverguenther commented Apr 28, 2025

Use an init container to set sticky bit permissions while we cannot use emptyDir yet

Related: kubernetes/kubernetes#110835

Copy link

changeset-bot bot commented Apr 28, 2025

🦋 Changeset detected

Latest commit: ccb8fca

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@openproject/helm-charts Minor

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@oliverguenther
Copy link
Member Author

@dominikkaminski could you help us evaluate the impact of those changes? Is there a hardened option that would be approved for the security guidelines of oD? We could make the initContainer opt-out, for example.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

1 participant