Skip to content

cartservice - unprivileged container #848

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 7 commits into from
Jun 9, 2022

Conversation

mathieu-benoit
Copy link
Contributor

@mathieu-benoit mathieu-benoit commented Jun 9, 2022

Setup cartservice to run as unprivileged container (other services will come later with future dedicated PRs).

@mathieu-benoit mathieu-benoit requested a review from a team as a code owner June 9, 2022 01:22
@mathieu-benoit mathieu-benoit marked this pull request as draft June 9, 2022 01:22
@github-actions
Copy link

github-actions bot commented Jun 9, 2022

🚲 PR staged at http://34.134.2.241

@github-actions
Copy link

github-actions bot commented Jun 9, 2022

🚲 PR staged at http://34.134.2.241

@github-actions
Copy link

github-actions bot commented Jun 9, 2022

🚲 PR staged at http://34.134.2.241

@mathieu-benoit mathieu-benoit marked this pull request as ready for review June 9, 2022 16:28
@mathieu-benoit
Copy link
Contributor Author

mathieu-benoit commented Jun 9, 2022

Ready for your review, thanks! Again it's just for cartservice for now, other services will come later.

The goal here is to have Online Boutique containers/apps running unprivileged (non root, etc.) in order to be easily deployed on secure environment (PSP, Gatekeeper, OpenShift, etc.). Evidence with Bank of Anthos here: GoogleCloudPlatform/bank-of-anthos#517. I will implement this later in there too.

Because I already had the implementation of this tested and working on my environment for cartservice, I just pushed this here to start :)

Copy link
Collaborator

@NimJay NimJay left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.
Thanks for doing this, @mathieu-benoit.
I've tested the staging URL — the cart works fine.

@github-actions
Copy link

github-actions bot commented Jun 9, 2022

🚲 PR staged at http://34.134.2.241

@mathieu-benoit mathieu-benoit merged commit d91b772 into main Jun 9, 2022
@mathieu-benoit mathieu-benoit deleted the mathieu-benoit/unprivileged-cartservice branch June 9, 2022 20:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants