Uploaded image for project: 'OpenShift API for Data Protection'
  1. OpenShift API for Data Protection
  2. OADP-5182

Operator best practices #20: Set the the pod and containers "runAsNonRoot" to true.

XMLWordPrintable

    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • ToDo
    • 0
    • 0.000
    • Very Likely
    • 0
    • None
    • Unset
    • Unknown
    • None

      Description of problem:

      https://docs.google.com/spreadsheets/d/12o_xZw1O7HN4Onagx8ferGVwKjq8VL_B6FBvCKozv7A/edit?gid=474648908#gid=474648908

      See row #20

      By default OADP can be shipped such that file system backups are disabled.  The podified datamover in velero v1.15 would allow OADP-1.5.x by default to use non root containers.

      Customers would obviously be allow to turn on FSB and privledged mode.

       

       

              spampatt@redhat.com Shubham Pampattiwar
              wnstb Wes Hayutin
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: