Fix Collabora (#361)
* try root for collabora * full root * privesc * mknod? * try another option * try lool user 101 * full 101 * exc + 101 * spacing * runasnonroot check * 101 0 101 * add pgid and uid * try something to override * Port setting to normal install and remove MKNOD
This commit is contained in:
@@ -9,7 +9,12 @@ image:
|
|||||||
tag: 6.4.7.5
|
tag: 6.4.7.5
|
||||||
pullPolicy: IfNotPresent
|
pullPolicy: IfNotPresent
|
||||||
|
|
||||||
startAsRoot: true
|
# Configure the Security Context for the Pod
|
||||||
|
podSecurityContext:
|
||||||
|
runAsNonRoot: false
|
||||||
|
runAsUser: null
|
||||||
|
runAsGroup: null
|
||||||
|
fsGroup: null
|
||||||
|
|
||||||
##
|
##
|
||||||
# Most other defaults are set in questions.yaml
|
# Most other defaults are set in questions.yaml
|
||||||
|
|||||||
@@ -360,75 +360,3 @@ questions:
|
|||||||
schema:
|
schema:
|
||||||
type: string
|
type: string
|
||||||
default: ""
|
default: ""
|
||||||
|
|
||||||
- variable: UMASK
|
|
||||||
group: "Advanced"
|
|
||||||
label: "UMASK"
|
|
||||||
description: "Sets the UMASK env var for LinuxServer.io (compatible) containers"
|
|
||||||
schema:
|
|
||||||
type: string
|
|
||||||
default: "002"
|
|
||||||
# Enable privileged
|
|
||||||
- variable: securityContext
|
|
||||||
group: "Advanced"
|
|
||||||
label: "Security Context"
|
|
||||||
schema:
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: privileged
|
|
||||||
label: "Enable privileged mode for Common-Chart based charts"
|
|
||||||
schema:
|
|
||||||
type: boolean
|
|
||||||
default: false
|
|
||||||
# Set Pod Security Policy
|
|
||||||
- variable: podSecurityContext
|
|
||||||
group: "Advanced"
|
|
||||||
label: "Pod Security Context"
|
|
||||||
schema:
|
|
||||||
type: dict
|
|
||||||
attrs:
|
|
||||||
- variable: runAsNonRoot
|
|
||||||
label: "runAsNonRoot"
|
|
||||||
schema:
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
- variable: runAsUser
|
|
||||||
label: "runAsUser"
|
|
||||||
description: "The UserID of the user running the application"
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 568
|
|
||||||
- variable: runAsGroup
|
|
||||||
label: "runAsGroup"
|
|
||||||
description: The groupID this App of the user running the application"
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 568
|
|
||||||
- variable: supplementalGroups
|
|
||||||
label: "supplementalGroups"
|
|
||||||
description: "Additional groups this App needs access to"
|
|
||||||
schema:
|
|
||||||
type: list
|
|
||||||
default: []
|
|
||||||
items:
|
|
||||||
- variable: Group
|
|
||||||
label: "Group"
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 568
|
|
||||||
- variable: fsGroup
|
|
||||||
label: "fsGroup"
|
|
||||||
description: "The group that should own ALL storage."
|
|
||||||
schema:
|
|
||||||
type: int
|
|
||||||
default: 568
|
|
||||||
- variable: fsGroupChangePolicy
|
|
||||||
label: "When should we take ownership?"
|
|
||||||
schema:
|
|
||||||
type: string
|
|
||||||
default: "OnRootMismatch"
|
|
||||||
enum:
|
|
||||||
- value: "OnRootMismatch"
|
|
||||||
description: "OnRootMismatch"
|
|
||||||
- value: "Always"
|
|
||||||
description: "Always"
|
|
||||||
|
|||||||
@@ -9,9 +9,9 @@ strategy:
|
|||||||
# Configure the Security Context for the Pod
|
# Configure the Security Context for the Pod
|
||||||
podSecurityContext:
|
podSecurityContext:
|
||||||
runAsNonRoot: false
|
runAsNonRoot: false
|
||||||
runAsUser: 102
|
runAsUser: null
|
||||||
runAsGroup: 102
|
runAsGroup: null
|
||||||
fsGroup: 568
|
fsGroup: null
|
||||||
|
|
||||||
services:
|
services:
|
||||||
main:
|
main:
|
||||||
|
|||||||
Reference in New Issue
Block a user