Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-66144

CBO: enable readOnlyRootFilesystem for machine-os-images

XMLWordPrintable

    • None
    • False
    • Hide

      None

      Show
      None
    • 2
    • None
    • None
    • None
    • Rejected
    • Metal Platform 280
    • 1
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Description of problem:

      Currently, we don't have the readOnlyRootFilesystem flag enabled for machine-os-images container due to the issue being fixed in this pr - https://github.com/openshift/machine-os-images/pull/72.
      Additionally, we want to remove the "/certs/ca/ironic" writable mount and reduce the exposed surface from a security standpoint. This depends on the the fix from this pr - https://github.com/openshift/ironic-image/pull/728.

              hroy@redhat.com Himanshu Roy
              hroy@redhat.com Himanshu Roy
              None
              None
              Jad Haj Yahya Jad Haj Yahya
              None
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated: