-
Bug
-
Resolution: Unresolved
-
Major
-
4.21
-
None
-
False
-
-
2
-
None
-
None
-
None
-
Rejected
-
Metal Platform 280, Metal Platform 281
-
2
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Currently, we don't have the readOnlyRootFilesystem flag enabled for machine-os-images container due to the issue being fixed in this pr - https://github.com/openshift/machine-os-images/pull/72.
Additionally, we want to remove the "/certs/ca/ironic" writable mount and reduce the exposed surface from a security standpoint. This depends on the the fix from this pr - https://github.com/openshift/ironic-image/pull/728.
- is blocked by
-
OCPBUGS-65971 The machine-os-images container writes to /coreos during runtime which will fail for readOnlyRootFS
-
- Verified
-
- links to