Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-42494

Set volume mount permissions explicitly in quadlet .container files

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Implementation of Feature Request SAT-42077 to add explicit mount options (rw/ro) to quadlet .container files for BSI SYS 1.6 A19 compliance.h2. Goal
      Update all quadlet .container files to explicitly declare volume mount permissions to meet compliance framework requirements.

      Acceptance Criteria

      • All quadlet .container files have explicit mount options specified (e.g., :rw or :ro)
      • Specifically update iop-core-kafka and iop-service-vmaas configurations that currently lack explicit mount options
      • No functional changes to existing behavior
      • All volume mounts maintain their intended read/write permissions

      Implementation Notes

      From Feature Request analysis:

      • Current state: Some volume declarations like 'iop-core-kafka-data:/var/lib/kafka/data' and 'iop-service-vmaas-data:/data' lack explicit permissions
      • Required: Add appropriate :rw or :ro suffix to all volume mount declarations
      • Compliance requirement: BSI SYS 1.6 A19

              ehelms@redhat.com Eric Helms
              ehelms@redhat.com Eric Helms
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: