From 06796750e40510802edc21ed5c957e6de3a444a8 Mon Sep 17 00:00:00 2001 From: Gustavo William Date: Mon, 5 Oct 2026 12:21:02 -0400 Subject: [PATCH] test: set runAsUser and runAsGroup in object-store and s3-client definitions The object-store and s3-client deployments in hack/object-store set runAsNonRoot without a numeric user, so the kubelet refuses to start them: - object-store: the RustFS image names its user instead of giving a number ("image has non-numeric user (rustfs), cannot verify user is non-root"). - s3-client: the AWS CLI image declares no user, which the kubelet treats as root ("image will run as root"). Run object-store as the rustfs user and group defined by the image (10001:10001), and s3-client as nobody (65534:65534), which the AWS CLI image already ships. Closes: #1145 Signed-off-by: Gustavo William --- hack/object-store/object-store-deployment.yaml | 2 ++ hack/object-store/s3-client.yaml | 2 ++ 2 files changed, 4 insertions(+) diff --git a/hack/object-store/object-store-deployment.yaml b/hack/object-store/object-store-deployment.yaml index 76a36585..4ecd1335 100644 --- a/hack/object-store/object-store-deployment.yaml +++ b/hack/object-store/object-store-deployment.yaml @@ -82,6 +82,8 @@ spec: drop: - ALL runAsNonRoot: true + runAsUser: 10001 # rustfs user ID + runAsGroup: 10001 # rustfs group ID seccompProfile: type: RuntimeDefault livenessProbe: diff --git a/hack/object-store/s3-client.yaml b/hack/object-store/s3-client.yaml index b70fb54a..57665c1c 100644 --- a/hack/object-store/s3-client.yaml +++ b/hack/object-store/s3-client.yaml @@ -57,6 +57,8 @@ spec: drop: - ALL runAsNonRoot: true + runAsUser: 65534 # nobody user ID + runAsGroup: 65534 # nobody group ID seccompProfile: type: RuntimeDefault securityContext: