Uploaded image for project: 'OpenShift Pipelines'
  1. OpenShift Pipelines
  2. SRVKP-1514

Reduced build privileges

XMLWordPrintable

    • Reduced build privileges
    • False
    • False
    • Done
    • SECFLOWOTL-55 - Enhance outerloop security
    • 66
    • 66% 66%
    • Undefined

      Goal

      As a cluster-admin, I want image build tasks to run as rootless builds in order to reduce the security risk of running privileges builds on the OpenShift cluster.

      Estimation

      M

      Acceptance Criteria

      • Buildah task can run in user namespaces and as a non-root container on the host
      • Buildah task can run as non-root inside the taskrun container

            cboudjna@redhat.com Chmouel Boudjnah
            ssadeghi@redhat.com Siamak Sadeghianfar
            Votes:
            3 Vote for this issue
            Watchers:
            9 Start watching this issue

              Created:
              Updated:
              Resolved: