cockroachdb / cockroachdb/docs

Current guidance on how to run containerized CRDB clusters has users running as root in the container

オープン
#8,416 コメント 23 件 リアクション 0 件 担当者 1 名 @mdlinville が担当を希望しています GitHub で見る
C-doc-improvement O-sales-eng P-0
主要言語
HTML
スター
212
フォーク
476
平均マージ
40分
マージ済み PR(30日)
3

説明

Keith McClellan (keith-mcclellan) commented:

Our current guidance, instructions, config files, etc for running CRDB in a containerized environment has cockroachdb running as root inside the container. This is a security vulnerability and needs to be addressed as soon as possible.

I checked our default configs and instructions for Helm, StatefulSets (static config), and Docker all run the crdb container as the root user. There’s also no mention of changing this in our Production Checklist. This was discovered during the work packaging the new K8s operator for OpenShift because it detects that we're trying to exec inside the container as root.

Jira Issue: DOC-772

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。