Skip to content

Conversation

@pantierra
Copy link
Contributor

@pantierra pantierra commented Dec 10, 2025

@pantierra
Copy link
Contributor Author

Check work. Now we have to wait and rebase until all upstream projects release the non-root container images.

@pantierra pantierra self-assigned this Dec 15, 2025
@pantierra pantierra force-pushed the feature/non-root-images branch from cee859a to 517d8c0 Compare December 19, 2025 15:26
@pantierra pantierra force-pushed the feature/non-root-images branch from 517d8c0 to 7023284 Compare January 5, 2026 12:40
@j08lue
Copy link
Member

j08lue commented Jan 8, 2026

@pantierra
Copy link
Contributor Author

Yes, STAC-Browser 4.0.0 is part of #376

@pantierra pantierra force-pushed the feature/non-root-images branch 2 times, most recently from aa9314e to 3b4e0e0 Compare January 13, 2026 19:45
@pantierra pantierra requested a review from ciaransweet January 13, 2026 19:45
initContainers:
- name: wait-for-pgstac-jobs
image: alpine/k8s:1.28.0
image: bitnami/kubectl:latest
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we use this one? Should it not be bitnamilegacy/kubectl:<something>?

Either way, I'd say ⛔ to bitnami.

Copy link
Contributor Author

@pantierra pantierra Jan 13, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It works. Even without the legacy part.

As far as i know this is the only (serious) one that runs as non-root. Maybe we should stick to alpine/k8s but use securityContext with it?!

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Weird. I'm not convinced when deployed, it will work, but not sure, maybe kubectl is a rare case of bitnami truly keeping it free..

@pantierra
Copy link
Contributor Author

All services are running now as non-root, but pgstac-pypgstac. @bitner, is there any release planned?

@pantierra pantierra force-pushed the feature/non-root-images branch 2 times, most recently from 447d2dd to 3b4e0e0 Compare January 13, 2026 20:15
@pantierra pantierra force-pushed the main branch 7 times, most recently from 6f0a6fe to 25dc65d Compare January 14, 2026 15:55
@pantierra pantierra force-pushed the feature/non-root-images branch from 3b4e0e0 to a8abf21 Compare January 15, 2026 16:16
@pantierra pantierra force-pushed the feature/non-root-images branch from a8abf21 to e211b95 Compare January 16, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

eoAPI and STAC Manager: Services should not run as root

4 participants