pingcap / pingcap/tidb-operator

Change to run all components as non root

Open
#3,907 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

priority:P2 type/feature-request
Dominant language
Go
Stars
1.3k
Forks
540
Avg merge
3d 2h
Merged PRs (30d)
18

Description

Feature Request

Is your feature request related to a problem? Please describe:

Now all containers of tidb-operator are run as root. Dockerfiles should be changed to build image as non-root for security practice.

Describe the feature you'd like:

Describe alternatives you've considered:

Teachability, Documentation, Adoption, Migration Strategy:

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating every Dockerfile and image-build entry point used by tidb-operator's components. Trace how the images are run in Kubernetes, then verify that all component images build and run as non-root without breaking their existing behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, kubernetes
Domain
devops, infrastructure, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.