fix(operator): 游戏 Pod 改以 UID 1000 运行并丢弃全部能力,prepare-data 初始化容器修正旧存档属主

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:23:49 +08:00
1 parent c1796bea17
commit 346a93921e
25 files changed
+555 -91

No files matched your search

+3 -3
View File
@@ -807,9 +807,9 @@ func TestReaperCronJob_Shape(t *testing.T) {
}
// The reaper is the one world-touching workload, so its identity is ROOT, not
// the control-plane's non-root uid: the worlds it archives and deletes are
// written by the game image's own UID (root for the images we ship), including
// Paper's mode-0600 files. DAC_OVERRIDE covers images with another UID.
// the control-plane's non-root uid: the worlds it archives and deletes sit in a
// root-owned storage root and hold Paper's mode-0600 files, whichever uid (the
// game uid, or root for a world an older release wrote) owns them.
if ps.SecurityContext == nil || ps.SecurityContext.RunAsNonRoot == nil || *ps.SecurityContext.RunAsNonRoot {
t.Error("reaper pod must NOT require non-root: root is the owner-matching identity for game-image worlds")
}