Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

make pod run as non-root mandatory #764

Open
nicolasburtey opened this issue Apr 20, 2021 · 0 comments
Open

make pod run as non-root mandatory #764

nicolasburtey opened this issue Apr 20, 2021 · 0 comments

Comments

@nicolasburtey
Copy link
Member

having some Pod running as root can be a security threat, because if someone were to get access to the Pod, then they could install everything they want on it and make further progress to the cluster.

Also, it seems some cloud provider (Openshift from RedHat) denies installation of pods with root access.

Some Pod currently running as root (list not exhaustive):

  • db backup
  • lnd
@nicolasburtey nicolasburtey transferred this issue from GaloyMoney/blink Mar 28, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant