初始提交:DSH 多租户平台(dshs)
This commit is contained in:
commit
43976fea6a
167 files changed
+24456
No files matched your search
@@ -0,0 +1,25 @@
|
||||
# §4.9 步骤 1:一次性特权 bootstrap,把 PVC 根 world-writable + sticky。
|
||||
# 必须在启用 PSA restricted 之前跑(此 namespace 不打 restricted 标签)。
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: dsh-users-bootstrap
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
ttlSecondsAfterFinished: 300
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
containers:
|
||||
- name: bootstrap
|
||||
image: busybox:1.36
|
||||
command: ["sh", "-c", "chmod 1777 /mnt && ls -ld /mnt"]
|
||||
securityContext:
|
||||
privileged: true
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /mnt
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
claimName: dsh-users
|
||||
@@ -0,0 +1,32 @@
|
||||
# §4.9 步骤 2:非 root init Job,目标 uid 建用户目录并 chmod 0700。
|
||||
# 验证非 root uid 能在 PVC 根写目录(依赖 bootstrap 的 chmod 1777)。
|
||||
apiVersion: batch/v1
|
||||
kind: Job
|
||||
metadata:
|
||||
name: dsh-u1-init
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
ttlSecondsAfterFinished: 300
|
||||
template:
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 100001
|
||||
fsGroup: 100001
|
||||
seccompProfile: { type: RuntimeDefault }
|
||||
containers:
|
||||
- name: init
|
||||
image: busybox:1.36
|
||||
command: ["sh", "-c", "mkdir -p /mnt/u1/ws /mnt/u1/home && chmod 0700 /mnt/u1 && ls -ldn /mnt/u1"]
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities: { drop: ["ALL"] }
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /mnt
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
claimName: dsh-users
|
||||
@@ -0,0 +1,11 @@
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: dsh-users
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
accessModes: [ReadWriteMany]
|
||||
storageClassName: longhorn
|
||||
resources:
|
||||
requests:
|
||||
storage: 1Gi
|
||||
@@ -0,0 +1,42 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
NS=dsh-poc
|
||||
UID_=100001
|
||||
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
||||
|
||||
pass() { echo "PASS: $*"; }
|
||||
fail() { echo "FAIL: $*"; exit 1; }
|
||||
|
||||
kubectl create namespace "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
|
||||
|
||||
echo "== 1. PVC bound =="
|
||||
kubectl apply -f "$HERE/pvc.yaml" >/dev/null
|
||||
kubectl wait -n "$NS" --for=jsonpath='{.status.phase}'=Bound pvc/dsh-users --timeout=120s
|
||||
pass "PVC dsh-users bound (Longhorn RWX)"
|
||||
|
||||
echo "== 2. bootstrap (privileged chmod 1777) =="
|
||||
kubectl apply -f "$HERE/bootstrap-job.yaml" >/dev/null
|
||||
kubectl wait -n "$NS" --for=condition=complete job/dsh-users-bootstrap --timeout=120s
|
||||
BOOT_LOG="$(kubectl logs -n "$NS" job/dsh-users-bootstrap)"
|
||||
echo "$BOOT_LOG"
|
||||
echo "$BOOT_LOG" | grep -q 'drwxrwxrwt' && pass "PVC root is world-writable+sticky" || fail "bootstrap chmod 1777 did not stick"
|
||||
|
||||
echo "== 3. init Job (non-root uid builds 0700 dir) =="
|
||||
kubectl apply -f "$HERE/init-job.yaml" >/dev/null
|
||||
kubectl wait -n "$NS" --for=condition=complete job/dsh-u1-init --timeout=120s
|
||||
INIT_LOG="$(kubectl logs -n "$NS" job/dsh-u1-init)"
|
||||
echo "$INIT_LOG"
|
||||
# ls -ldn output: drwx------ 2 100001 100001 ... /mnt/u1
|
||||
echo "$INIT_LOG" | grep -qE 'drwx------.*100001' && pass "u1 dir is 0700 owned by uid $UID_" || fail "init Job could not create/chown u1 (non-root uid cannot write PVC root)"
|
||||
|
||||
echo "== 4. test Pod (subPath + runAsUser read/write) =="
|
||||
kubectl apply -f "$HERE/test-pod.yaml" >/dev/null
|
||||
kubectl wait -n "$NS" --for=jsonpath='{.status.phase}'=Succeeded pod/dsh-u1-test --timeout=120s
|
||||
TEST_LOG="$(kubectl logs -n "$NS" pod/dsh-u1-test)"
|
||||
echo "$TEST_LOG"
|
||||
echo "$TEST_LOG" | grep -q '^hello$' && pass "subPath write/read works" || fail "subPath mount read/write failed"
|
||||
echo "$TEST_LOG" | grep -qE 'drwx------.*100001' && pass "mounted dir is 0700 uid $UID_" || fail "mounted dir owner/perm wrong"
|
||||
|
||||
echo
|
||||
echo "ALL ITEM-1 CHECKS PASSED"
|
||||
@@ -0,0 +1,35 @@
|
||||
# §4.3:subPath 叶子挂载 + runAsUser,验证目标 uid 能读写自己的目录。
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: dsh-u1-test
|
||||
namespace: dsh-poc
|
||||
spec:
|
||||
restartPolicy: Never
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 100001
|
||||
fsGroup: 100001
|
||||
seccompProfile: { type: RuntimeDefault }
|
||||
containers:
|
||||
- name: test
|
||||
image: busybox:1.36
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
- |
|
||||
echo hello > /var/lib/dshs/users/u1/ws/probe.txt
|
||||
cat /var/lib/dshs/users/u1/ws/probe.txt
|
||||
ls -ldn /var/lib/dshs/users/u1
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities: { drop: ["ALL"] }
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /var/lib/dshs/users/u1
|
||||
subPath: u1
|
||||
volumes:
|
||||
- name: data
|
||||
persistentVolumeClaim:
|
||||
claimName: dsh-users
|
||||
Reference in new issue
Block a user