coder / coder/envbuilder

Adding CA certificate into Coder template failing build (k8s)

Đang mở
#464 6 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Go
Star
300
Fork
64
Merge trung bình
20 phút
Pull request đã merge (30 ngày)
1

Mô tả

Using the [devcontainer Coder template](https://github.com/coder/coder/blob/main/examples/templates/kubernetes-devcontainer/main.tf) I'm seeing the following issue when mounting my CA certificates:

```bash
error: temp remount: temp remount: bind mount /ca-certs/ca-file => /.envbuilder/mnt/ca-certs/ca-file: permission denied
```

Adding certificate directory to ENV:
```hcl

locals {
...
"SSL_CERT_DIR" : "/ca-certs"
//or
"SSL_CERT_FILE": "/ca-certs/ca-file"
}
```

```hcl
resource "kubernetes_deployment" "main" {
...

spec {
template {
spec {
...
volume_mount {
name = "ca-file"
mount_path = "/ca-certs/ca-file"
}
}

volume {
name = "ca-file"
secret {
secret_name = "coder-tls"
}
...
}
}
```

Just trying to have the container built trust my private PKI services.

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Hướng nghiên cứu

Start with examples/templates/kubernetes-devcontainer/main.tf and reproduce the CA certificate mount in Kubernetes using the reported configuration. Trace the environment builder's handling of the /ca-certs/ca-file bind mount and verify that a build can trust the private PKI without the permission-denied remount error.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
go, kubernetes
Lĩnh vực
infrastructure, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
38/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.