初始提交:DSH 多租户平台(dshs)

This commit is contained in:
admin committed 2026-09-13 16:18:10 +08:00
commit 43976fea6a
167 files changed
+24456

No files matched your search

@@ -0,0 +1,25 @@
# §4.9 步骤 1:一次性特权 bootstrap,把 PVC 根 world-writable + sticky。
# 必须在启用 PSA restricted 之前跑(此 namespace 不打 restricted 标签)。
apiVersion: batch/v1
kind: Job
metadata:
name: dsh-users-bootstrap
namespace: dsh-poc
spec:
ttlSecondsAfterFinished: 300
template:
spec:
restartPolicy: Never
containers:
- name: bootstrap
image: busybox:1.36
command: ["sh", "-c", "chmod 1777 /mnt && ls -ld /mnt"]
securityContext:
privileged: true
volumeMounts:
- name: data
mountPath: /mnt
volumes:
- name: data
persistentVolumeClaim:
claimName: dsh-users
+32
View File
@@ -0,0 +1,32 @@
# §4.9 步骤 2:非 root init Job,目标 uid 建用户目录并 chmod 0700。
# 验证非 root uid 能在 PVC 根写目录(依赖 bootstrap 的 chmod 1777)。
apiVersion: batch/v1
kind: Job
metadata:
name: dsh-u1-init
namespace: dsh-poc
spec:
ttlSecondsAfterFinished: 300
template:
spec:
restartPolicy: Never
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 100001
fsGroup: 100001
seccompProfile: { type: RuntimeDefault }
containers:
- name: init
image: busybox:1.36
command: ["sh", "-c", "mkdir -p /mnt/u1/ws /mnt/u1/home && chmod 0700 /mnt/u1 && ls -ldn /mnt/u1"]
securityContext:
allowPrivilegeEscalation: false
capabilities: { drop: ["ALL"] }
volumeMounts:
- name: data
mountPath: /mnt
volumes:
- name: data
persistentVolumeClaim:
claimName: dsh-users
+11
View File
@@ -0,0 +1,11 @@
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: dsh-users
namespace: dsh-poc
spec:
accessModes: [ReadWriteMany]
storageClassName: longhorn
resources:
requests:
storage: 1Gi
+42
View File
@@ -0,0 +1,42 @@
#!/usr/bin/env bash
set -euo pipefail
NS=dsh-poc
UID_=100001
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
pass() { echo "PASS: $*"; }
fail() { echo "FAIL: $*"; exit 1; }
kubectl create namespace "$NS" --dry-run=client -o yaml | kubectl apply -f - >/dev/null
echo "== 1. PVC bound =="
kubectl apply -f "$HERE/pvc.yaml" >/dev/null
kubectl wait -n "$NS" --for=jsonpath='{.status.phase}'=Bound pvc/dsh-users --timeout=120s
pass "PVC dsh-users bound (Longhorn RWX)"
echo "== 2. bootstrap (privileged chmod 1777) =="
kubectl apply -f "$HERE/bootstrap-job.yaml" >/dev/null
kubectl wait -n "$NS" --for=condition=complete job/dsh-users-bootstrap --timeout=120s
BOOT_LOG="$(kubectl logs -n "$NS" job/dsh-users-bootstrap)"
echo "$BOOT_LOG"
echo "$BOOT_LOG" | grep -q 'drwxrwxrwt' && pass "PVC root is world-writable+sticky" || fail "bootstrap chmod 1777 did not stick"
echo "== 3. init Job (non-root uid builds 0700 dir) =="
kubectl apply -f "$HERE/init-job.yaml" >/dev/null
kubectl wait -n "$NS" --for=condition=complete job/dsh-u1-init --timeout=120s
INIT_LOG="$(kubectl logs -n "$NS" job/dsh-u1-init)"
echo "$INIT_LOG"
# ls -ldn output: drwx------ 2 100001 100001 ... /mnt/u1
echo "$INIT_LOG" | grep -qE 'drwx------.*100001' && pass "u1 dir is 0700 owned by uid $UID_" || fail "init Job could not create/chown u1 (non-root uid cannot write PVC root)"
echo "== 4. test Pod (subPath + runAsUser read/write) =="
kubectl apply -f "$HERE/test-pod.yaml" >/dev/null
kubectl wait -n "$NS" --for=jsonpath='{.status.phase}'=Succeeded pod/dsh-u1-test --timeout=120s
TEST_LOG="$(kubectl logs -n "$NS" pod/dsh-u1-test)"
echo "$TEST_LOG"
echo "$TEST_LOG" | grep -q '^hello$' && pass "subPath write/read works" || fail "subPath mount read/write failed"
echo "$TEST_LOG" | grep -qE 'drwx------.*100001' && pass "mounted dir is 0700 uid $UID_" || fail "mounted dir owner/perm wrong"
echo
echo "ALL ITEM-1 CHECKS PASSED"
+35
View File
@@ -0,0 +1,35 @@
# §4.3:subPath 叶子挂载 + runAsUser,验证目标 uid 能读写自己的目录。
apiVersion: v1
kind: Pod
metadata:
name: dsh-u1-test
namespace: dsh-poc
spec:
restartPolicy: Never
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 100001
fsGroup: 100001
seccompProfile: { type: RuntimeDefault }
containers:
- name: test
image: busybox:1.36
command:
- sh
- -c
- |
echo hello > /var/lib/dshs/users/u1/ws/probe.txt
cat /var/lib/dshs/users/u1/ws/probe.txt
ls -ldn /var/lib/dshs/users/u1
securityContext:
allowPrivilegeEscalation: false
capabilities: { drop: ["ALL"] }
volumeMounts:
- name: data
mountPath: /var/lib/dshs/users/u1
subPath: u1
volumes:
- name: data
persistentVolumeClaim:
claimName: dsh-users