Repository navigation
Commit d5e4c4c
committed
Robusta fork: run entrypoint without sudo under non-root UIDs (OpenShift)
OpenShift's restricted-v2 SCC forces containers to run as a random
non-root UID *and* sets no_new_privs=1, which blocks sudo outright
(even when sudo is only de-escalating from root to nobody). Upstream's
run.sh assumed the container always starts as root and unconditionally
shelled out to `sudo -E -u nobody`, so the pod crashed before migrations
could run.
Wrap the privilege drop in a small helper that checks `id -u`: when
we're already non-root, invoke the binary directly. This keeps the
upstream behavior on platforms that start as root (drop to `nobody`)
while letting OpenShift run unchanged.
Also relax /app permissions to `chgrp 0 + chmod g=u` so the random UID
(which has gid 0 as a supplemental group on OpenShift) can read the
release and write to /app/.pgdelta-cache.1 parent c0c3b8b commit d5e4c4c
2 files changed
Lines changed: 21 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
94 | 94 | | |
95 | 95 | | |
96 | 96 | | |
97 | | - | |
| 97 | + | |
| 98 | + | |
98 | 99 | | |
99 | 100 | | |
100 | 101 | | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
101 | 106 | | |
102 | 107 | | |
103 | 108 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
94 | 94 | | |
95 | 95 | | |
96 | 96 | | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
97 | 110 | | |
98 | | - | |
| 111 | + | |
99 | 112 | | |
100 | 113 | | |
101 | 114 | | |
102 | | - | |
| 115 | + | |
103 | 116 | | |
104 | 117 | | |
105 | 118 | | |
| |||
0 commit comments