1
0
mirror of https://github.com/bigchaindb/bigchaindb.git synced 2024-06-17 10:03:20 +02:00

Merge pull request #1723 from bigchaindb/run-mma-mba-non-root

Run mongodb monitoring and backup agents as non-root user
This commit is contained in:
Ahmed Muawia Khan 2017-08-17 15:12:19 +02:00 committed by GitHub
commit a05cdb4413
4 changed files with 9 additions and 9 deletions

View File

@ -20,5 +20,5 @@ RUN apt update \
COPY mongodb_backup_agent_entrypoint.bash /
RUN chown -R mongodb-mms-agent:mongodb-mms-agent /etc/mongodb-mms/
VOLUME /etc/mongod/ssl /etc/mongod/ca
#USER mongodb-mms-agent - BUG(Krish) Uncomment after tests are complete
USER mongodb-mms-agent
ENTRYPOINT ["/mongodb_backup_agent_entrypoint.bash"]

View File

@ -54,12 +54,12 @@ spec:
- name: mdb-bak-certs
secret:
secretName: mdb-bak-certs
defaultMode: 0400
defaultMode: 0404
- name: ca-auth
secret:
secretName: ca-auth
defaultMode: 0400
defaultMode: 0404
- name: cloud-manager-credentials
secret:
secretName: cloud-manager-credentials
defaultMode: 0400
defaultMode: 0404

View File

@ -54,5 +54,5 @@ RUN apt update \
COPY mongodb_mon_agent_entrypoint.bash /
RUN chown -R mongodb-mms-agent:mongodb-mms-agent /etc/mongodb-mms/
VOLUME /etc/mongod/ssl /etc/mongod/ca
#USER mongodb-mms-agent - BUG(Krish) Uncomment after tests are complete
ENTRYPOINT ["/mongodb_mon_agent_entrypoint.bash"]
USER mongodb-mms-agent
ENTRYPOINT ["/mongodb_mon_agent_entrypoint.bash"]

View File

@ -54,12 +54,12 @@ spec:
- name: mdb-mon-certs
secret:
secretName: mdb-mon-certs
defaultMode: 0400
defaultMode: 0404
- name: ca-auth
secret:
secretName: ca-auth
defaultMode: 0400
defaultMode: 0404
- name: cloud-manager-credentials
secret:
secretName: cloud-manager-credentials
defaultMode: 0400
defaultMode: 0404