-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
config: fix runAsUser inconsistency with images 🍨 #3342
config: fix runAsUser inconsistency with images 🍨 #3342
Conversation
The distroless `nonroot` image define a user with the uid 65532 and not 1001. The deployment should use that uid to make sure it works anywhere. Signed-off-by: Vincent Demeester <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: sbwsg The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This looks good, thanks.
Perhaps we should provide some mechanism to override that UID, or at least document it in the .ko.yaml
too, so that if someone uses a different base image, they don't get a bad surprise.
/lgtm |
|
/retest |
Port of tektoncd/pipeline#3342: The distroless nonroot image define a user with the uid 65532 and not 1001. The deployment should use that uid to make sure it works anywhere. Fixes tektoncd#781 Signed-off-by: Dibyo Mukherjee <[email protected]>
Port of tektoncd/pipeline#3342: The distroless nonroot image define a user with the uid 65532 and not 1001. The deployment should use that uid to make sure it works anywhere. Fixes #781 Signed-off-by: Dibyo Mukherjee <[email protected]>
Port of tektoncd/pipeline#3342: The distroless nonroot image define a user with the uid 65532. The deployment should use that uid to make sure it works anywhere.
Port of tektoncd/pipeline#3342: The distroless nonroot image define a user with the uid 65532. The deployment should use that uid to make sure it works anywhere.
Changes
Closes #3273
The distroless
nonroot
image define a user with the uid 65532 andnot 1001. The deployment should use that uid to make sure it works anywhere.
Signed-off-by: Vincent Demeester [email protected]
/cc @imjasonh @mattmoor @tektoncd/core-maintainers
/kind bug
Submitter Checklist
These are the criteria that every PR should meet, please check them off as you
review them:
See the contribution guide for more details.
Double check this list of stuff that's easy to miss:
cmd
dir, please updatethe release Task to build and release this image.
Reviewer Notes
If API changes are included, additive changes must be approved by at least two OWNERS and backwards incompatible changes must be approved by more than 50% of the OWNERS, and they must first be added in a backwards compatible way.
Release Notes