diff --git a/internal/platform/distributed_test.go b/internal/platform/distributed_test.go index afc3977..32b55a7 100644 --- a/internal/platform/distributed_test.go +++ b/internal/platform/distributed_test.go @@ -75,8 +75,18 @@ func TestNodeControlSocketIsAPIOnly(t *testing.T) { } } if d.Name != SAAPI { + if len(d.Spec.Template.Spec.SecurityContext.SupplementalGroups) != 0 { + t.Fatal("host socket group leaked to", d.Name) + } continue } + groups := d.Spec.Template.Spec.SecurityContext.SupplementalGroups + if len(groups) != 1 || groups[0] != 65532 { + t.Fatal("API lacks host socket group", groups) + } + if *d.Spec.Template.Spec.SecurityContext.RunAsUser != nonRootUID || *d.Spec.Template.Spec.SecurityContext.RunAsGroup != nonRootUID { + t.Fatal("API identity changed") + } if d.Spec.Template.Spec.NodeSelector["kubernetes.io/hostname"] != "controller" { t.Fatal("API can run away from socket") } diff --git a/internal/platform/workloads.go b/internal/platform/workloads.go index 34f1264..6b7af31 100644 --- a/internal/platform/workloads.go +++ b/internal/platform/workloads.go @@ -489,6 +489,10 @@ func APIDeployment(p Params) *appsv1.Deployment { container.Env = append(container.Env, corev1.EnvVar{Name: "FELIS_NODE_CONTROL_SOCKET", Value: p.NodeControlSocket}) } deployment := controlPlaneDeployment(p, SAAPI, container, volumes) + if p.NodeControlSocket != "" { + // The host socket uses a dedicated group; preserve the API's existing UID and volume identity. + deployment.Spec.Template.Spec.SecurityContext.SupplementalGroups = []int64{65532} + } if p.NodeControlNode != "" && p.ControllerNode == "" { deployment.Spec.Template.Spec.NodeSelector = map[string]string{"kubernetes.io/hostname": p.NodeControlNode} }