-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
4.21
-
None
-
False
-
-
2
-
None
-
None
-
None
-
Rejected
-
Metal Platform 280
-
1
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Currently, we don't have the readOnlyRootFilesystem flag enabled for machine-os-images container due to the issue being fixed in this pr - https://github.com/openshift/machine-os-images/pull/72.
Additionally, we want to remove the "/certs/ca/ironic" writable mount and reduce the exposed surface from a security standpoint. This depends on the the fix from this pr - https://github.com/openshift/ironic-image/pull/728.
- is blocked by
-
OCPBUGS-65969 Set the tls cacert path to writable mount when the IRONIC_CACERT_FILE is unset
-
- POST
-
-
OCPBUGS-65971 The machine-os-images container writes to /coreos during runtime which will fail for readOnlyRootFS
-
- MODIFIED
-
- links to