Unverified Commit 1b49b4df authored by Lemon-miaow's avatar Lemon-miaow
Browse files

fix: grant API the dedicated node-control socket group

parent 3327c134
Loading
Loading
Loading
Loading
+10 −0
Changes for internal/platform/distributed_test.go: 10 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -75,8 +75,18 @@ func TestNodeControlSocketIsAPIOnly(t *testing.T) {
			}
		}
		if d.Name != SAAPI {
			if len(d.Spec.Template.Spec.SecurityContext.SupplementalGroups) != 0 {
				t.Fatal("host socket group leaked to", d.Name)
			}
			continue
		}
		groups := d.Spec.Template.Spec.SecurityContext.SupplementalGroups
		if len(groups) != 1 || groups[0] != 65532 {
			t.Fatal("API lacks host socket group", groups)
		}
		if *d.Spec.Template.Spec.SecurityContext.RunAsUser != nonRootUID || *d.Spec.Template.Spec.SecurityContext.RunAsGroup != nonRootUID {
			t.Fatal("API identity changed")
		}
		if d.Spec.Template.Spec.NodeSelector["kubernetes.io/hostname"] != "controller" {
			t.Fatal("API can run away from socket")
		}
+4 −0
Changes for internal/platform/workloads.go: 4 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -489,6 +489,10 @@ func APIDeployment(p Params) *appsv1.Deployment {
		container.Env = append(container.Env, corev1.EnvVar{Name: "FELIS_NODE_CONTROL_SOCKET", Value: p.NodeControlSocket})
	}
	deployment := controlPlaneDeployment(p, SAAPI, container, volumes)
	if p.NodeControlSocket != "" {
		// The host socket uses a dedicated group; preserve the API's existing UID and volume identity.
		deployment.Spec.Template.Spec.SecurityContext.SupplementalGroups = []int64{65532}
	}
	if p.NodeControlNode != "" && p.ControllerNode == "" {
		deployment.Spec.Template.Spec.NodeSelector = map[string]string{"kubernetes.io/hostname": p.NodeControlNode}
	}