• Icon: Epic Epic
    • Resolution: Done
    • Icon: Major Major
    • None
    • None
    • virtiofsd
    • Run virtiofsd unprivileged for CNV
    • Medium
    • Red Hat OpenShift Virtualization
    • 0% To Do, 0% In Progress, 100% Done
    • rhel-sst-virtualization-storage
    • ssg_virtualization
    • 8
    • False
    • Hide

      None

      Show
      None

      Description

      CNV wants to run virtiofsd unprivileged. Some basic support has been already added by German which allows for singe uid/gid.

       

      One can also run virtiofsd inside a user namespace to to support arbitrary uid/gid. 

      As per discussions with Adam Litke, support for unprivileged virtiofsd has been identified as one of the core requirements for CNV.

      Hence I am creating this Epic to keep track of all the bugs/issues/stories associated with this Epic. Will be easy to have discussions and keep track of various issues in a single place.

      Acceptance Criteria

      A list of specific needs or objectives must be delivered to satisfy the epic.

      < What needs to be developed in order for this epic to satisfy the intent of the work? >

      • Verify X
      • Verify Y
      • Verify Z  

      What SSTs and Layered Product teams should review this?

            [RHEL-9921] Run virtiofsd unprivileged for CNV

            Close this issue as the issues in this epic are all done.

            Tingting Mao added a comment - Close this issue as the issues in this epic are all done.

            This will be a first approach, running virtiofsd without any privilege and without a user namespace. We already do that for configMaps, secrets, serviceAccounts and downwardAPIs, but extends it for PVs

              virtiofs: Run unprivileged without feature gate
             https://github.com/kubevirt/kubevirt/pull/10657

            German Maglione added a comment - This will be a first approach, running virtiofsd without any privilege and without a user namespace. We already do that for configMaps, secrets, serviceAccounts and downwardAPIs, but extends it for PVs   virtiofs: Run unprivileged without feature gate   https://github.com/kubevirt/kubevirt/pull/10657

            Marking this epic as blocking CNV-27131 because there is no way to delivering virtiofs in CNV without this epic completion.

            Dan Kenigsberg added a comment - Marking this epic as blocking CNV-27131 because there is no way to delivering virtiofs in CNV without this epic completion.

              gmaglion German Maglione
              rhn-engineering-vgoyal Vivek Goyal
              German Maglione, Hanna Czenczek, Jano Tomko
              Tingting Mao Tingting Mao
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: