Files
dsh_shenxian/deploy/08-bootstrap.yaml
T

37 lines
1.3 KiB
YAML
Raw Normal View History

# 一次性权限提升 Job:把共享 RWX PVC 根 chmod 1777(world-writable + sticky),
# 让后续各用户的非 root initContainer 能在根下建自己的 <userId>/ 目录
# (docs/k8s.md §4.9 第 1 步)。initContainer 挂的是 PVC **根**,不做 subPath。
#
# ⚠️ 只在 namespace 打 PSA restricted **之前** apply(见 07-psa.yaml 头注释)。
# 跑完可删,或留着(restartPolicy Never + 一次性效果,幂等)。
#
# 用控制面镜像(node:22-slim,已推 ACR)而非 busybox:集群拉不动 docker.io。
apiVersion: batch/v1
kind: Job
metadata:
name: dsh-users-bootstrap
namespace: dsh
spec:
ttlSecondsAfterFinished: 300
template:
spec:
restartPolicy: Never
automountServiceAccountToken: false
imagePullSecrets:
- name: dsh-acr-pull
containers:
- name: chmod-root
image: registry.example.com/dsh/dshs:0.2.0
command: ["sh", "-c", "chmod 1777 /mnt"]
securityContext:
runAsUser: 0 # 需 root 才能 chmod;本 Job 跑在 PSA restricted 之前
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
volumeMounts:
- name: data-root
mountPath: /mnt
volumes:
- name: data-root
persistentVolumeClaim:
claimName: dsh-users