Uploaded image for project: 'OpenShift BuildConfig'
  1. OpenShift BuildConfig
  2. OCPBUILD-45

Use Kubernetes user namespaces in build controller

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Won't Do
    • Icon: Minor Minor
    • None
    • None
    • None
    • None
    • Use Kubernetes user namespaces in build controller
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • Done
    • OCPSTRAT-198 - Secure-by-default image builds
    • OCPSTRAT-198Secure-by-default image builds

      Epic Goal

      Build controller (BuildConfigs) uses Kubernetes user namespace in order to run OpenShift build pods in the user namespaces

      Why is this important?

      To enable any authenticated user on OpenShift to run image builds through BuildConfigs without requiring additional privileges (e.g. builder service account) for OpenShift build pods that are not available to all authenticated users and all pods.

      Acceptance Criteria

      • Build pods can run in the user namespace using the Kubernetes user namespaces
      • Build pods can run with the default service account and the user-namespace-aware equivalent of "restricted" SCC

              rhn-engineering-nalin Nalin Dahyabhai
              rh-ee-ssadeghi Siamak Sadeghianfar
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: