Update security-context with readOnlyRootFilesystem: true to Mount root filesystem as read-only in Shared Resources containers #407
+7
−3
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Added security-context with readOnlyRootFilesystem: true to node_daemonset.yaml and webhook_deployment.yaml for the shared-resource containers in openshift-builds namespace.
To test the changes,
oc exec -it -n openshift-builds -c node-driver-registrar -- /bin/sh
touch /test_sr-node_readonly.txt -> This will give error -> touch: cannot touch '/test_sr-node_readonly.txt': Read-only file system -> Proves the changes are in place
Similarly for other containers:
oc exec -it -n openshift-builds -c hostpath -- /bin/sh
touch /test_sr-hostpath_readonly.txt -> This will give error -> touch: cannot touch '/test_sr-hostpath_readonly.txt': Read-only file system -> Proves the changes are in place
oc exec -it -n openshift-builds -c shared-resource-csi-driver-webhook -- /bin/sh
touch /test_webhook_readonly.txt -> This will give error -> touch: cannot touch '/test_webhook_readonly.txt': Read-only file system -> Proves the changes are in place