Uploaded image for project: 'Secret Store CSI for Red Hat OpenShift'
  1. Secret Store CSI for Red Hat OpenShift
  2. SSCSI-201

Investigate: Allow file ownership to be set for secrets

XMLWordPrintable

    • Icon: Spike Spike
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • 8
    • False
    • Hide

      None

      Show
      None
    • False
    • OAPE Sprint 272
    • 1

      As of now the SS-CSI secrets are mounted with root:root

      There is an issue open on upstream: https://github.com/kubernetes-sigs/secrets-store-csi-driver/issues/858

      Analyze and come up with a solution for it because addressing this issue is important to run workloads with reduced privileges while keeping the secrets files not world (i.e., others) readable.

      Acceptance criterion:

      Working solution proposal and draft PR with working e2e test submitted upstream.

              rh-ee-mykastur Mytreya Kasturi
              rh-ee-mykastur Mytreya Kasturi
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: