-
Epic
-
Resolution: Done
-
Critical
-
None
-
Reduced build privileges
-
False
-
False
-
Done
-
SECFLOWOTL-55 - Enhance outerloop security
-
33% To Do, 0% In Progress, 67% Done
-
Undefined
-
Goal
As a cluster-admin, I want image build tasks to run as rootless builds in order to reduce the security risk of running privileges builds on the OpenShift cluster.
Estimation
M
Acceptance Criteria
- Buildah task can run in user namespaces and as a non-root container on the host
- Buildah task can run as non-root inside the taskrun container
- is documented by
-
RHDEVDOCS-3306 Document running image build tasks as unprivileged builds
- Closed
-
RHDEVDOCS-4200 Document running image build tasks as unprivileged builds
- Closed
- is related to
-
SRVKP-2232 R&D Run buildah with default service account
- To Do
- relates to
-
SRVKP-1312 R&D Reduced build privileges
- Closed