37 lines
1.3 KiB
YAML
37 lines
1.3 KiB
YAML
# 一次性权限提升 Job:把共享 RWX PVC 根 chmod 1777(world-writable + sticky),
|
||||
|
|
# 让后续各用户的非 root initContainer 能在根下建自己的 <userId>/ 目录
|
|||
|
|
# (docs/k8s.md §4.9 第 1 步)。initContainer 挂的是 PVC **根**,不做 subPath。
|
|||
|
|
#
|
|||
|
|
# ⚠️ 只在 namespace 打 PSA restricted **之前** apply(见 07-psa.yaml 头注释)。
|
|||
|
|
# 跑完可删,或留着(restartPolicy Never + 一次性效果,幂等)。
|
|||
|
|
#
|
|||
|
|
# 用控制面镜像(node:22-slim,已推 ACR)而非 busybox:集群拉不动 docker.io。
|
|||
|
|
apiVersion: batch/v1
|
|||
|
|
kind: Job
|
|||
|
|
metadata:
|
|||
|
|
name: dsh-users-bootstrap
|
|||
|
|
namespace: dsh
|
|||
|
|
spec:
|
|||
|
|
ttlSecondsAfterFinished: 300
|
|||
|
|
template:
|
|||
|
|
spec:
|
|||
|
|
restartPolicy: Never
|
|||
|
|
automountServiceAccountToken: false
|
|||
|
|
imagePullSecrets:
|
|||
|
|
- name: dsh-acr-pull
|
|||
|
|
containers:
|
|||
|
|
- name: chmod-root
|
|||
|
|
image: registry.example.com/dsh/dshs:0.2.0
|
|||
|
|
command: ["sh", "-c", "chmod 1777 /mnt"]
|
|||
|
|
securityContext:
|
|||
|
|
runAsUser: 0 # 需 root 才能 chmod;本 Job 跑在 PSA restricted 之前
|
|||
|
|
allowPrivilegeEscalation: false
|
|||
|
|
capabilities:
|
|||
|
|
drop: ["ALL"]
|
|||
|
|
volumeMounts:
|
|||
|
|
- name: data-root
|
|||
|
|
mountPath: /mnt
|
|||
|
|
volumes:
|
|||
|
|
- name: data-root
|
|||
|
|
persistentVolumeClaim:
|
|||
|
|
claimName: dsh-users
|