Skip to content

Conversation

@lmilleri
Copy link
Member

@lmilleri lmilleri commented May 21, 2024

Changed SecurityContext for KBS containers (first step in the direction of running non-root containers)
Also, created 2 additional emptyDir volumes and mounted to kbs container
to allow having r/w access to the kbs filesystem.
Newly introduced functions:

  • createConfidentialContainersVolume
  • createDefaultRepositoryVolume

@lmilleri lmilleri requested a review from bpradipt May 21, 2024 11:04
@lmilleri lmilleri changed the title Trustee containers as non-privileged Add securityContext for the KBS deployment pod May 23, 2024
Copy link
Member

@bpradipt bpradipt left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@bpradipt bpradipt merged commit 4f65b4a into confidential-containers:main May 23, 2024
@lmilleri lmilleri deleted the rootless branch May 28, 2024 09:03
lmilleri pushed a commit to lmilleri/trustee-operator that referenced this pull request Jul 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants