Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-42147

haproxy binary capabilities in bootc images

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Do
    • Icon: Normal Normal
    • None
    • 4.18
    • Networking / router
    • None
    • None
    • 0
    • NE Sprint 259
    • 1
    • Rejected
    • False
    • Hide

      None

      Show
      None

      Description of problem:

      When embedding containers with MicroShift to run it using bootc we encountered an issue with the capabilities in the haproxy binary.
      According to https://github.com/openshift/router/blob/master/images/router/haproxy/Dockerfile#L9C1-L10C1 the cap_net_bind_service is added so that it can use ports below 1024.
      When embedding this container in bootc the capabilities are lost (See https://github.com/ostreedev/ostree-rs-ext/issues/654 and https://github.com/ostreedev/ostree-rs-ext/issues/655).
      While this is a bug in ostree, does haproxy need to be able to bind to privileged ports?
          

      Version-Release number of selected component (if applicable):

      4.18
          

      How reproducible:

      
          

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

      
          

      Expected results:

      
          

      Additional info:

      
          

            mmasters1@redhat.com Miciah Masters
            pacevedo@redhat.com Pablo Acevedo Montserrat
            Hongan Li Hongan Li
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: