Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PostgreSQL - Run the init non root #178

Open
megian opened this issue Nov 8, 2022 · 1 comment
Open

PostgreSQL - Run the init non root #178

megian opened this issue Nov 8, 2022 · 1 comment
Assignees
Labels
enhancement New feature or request

Comments

@megian
Copy link
Contributor

megian commented Nov 8, 2022

Context

The current PostgreSQL init requires obviously special permissions to set the volume permissions. Check if this can be prevented by using Delegating volume permission and ownership change to CSI driver.

Alternatives

Keep it less secure as is

@megian megian added the enhancement New feature or request label Nov 8, 2022
@megian megian self-assigned this Nov 8, 2022
@megian
Copy link
Contributor Author

megian commented Jan 5, 2024

The documentation still states that the volumePermission init container would be required. However the TLS key has also the right permission of 600without the volumePermission initcontainer.

$ ls -l /opt/bitnami/postgresql/certs/tls.key
-rw------- 1 1001 1001 3272 Jan  5 12:39 /opt/bitnami/postgresql/certs/tls.key
``

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant