ci: use host docker gid for envoybuild#23803
Merged
lizan merged 1 commit intoenvoyproxy:mainfrom Nov 2, 2022
Merged
Conversation
Signed-off-by: Lizan Zhou <lizan@tetrate.io>
Member
Author
|
cc @mum4k, the last failure with new image is https://dev.azure.com/cncf/envoy/_build/results?buildId=119624&view=logs&j=de8454aa[…]-5422-9f4b-1f3899ba6707&t=d285e0b0-bdfb-593c-c50f-c31c5e3531c1 |
phlax
approved these changes
Nov 2, 2022
Member
Author
|
/backport |
phlax
pushed a commit
to phlax/envoy
that referenced
this pull request
Nov 3, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Ryan Northey <ryan@synca.io>
phlax
pushed a commit
to phlax/envoy
that referenced
this pull request
Nov 3, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Ryan Northey <ryan@synca.io>
phlax
pushed a commit
that referenced
this pull request
Nov 3, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Ryan Northey <ryan@synca.io>
dio
added a commit
to dio/envoy
that referenced
this pull request
Nov 4, 2022
…ts of test data to fix flaky tests Cherry-picked from: - envoyproxy#23803 (7ac5336) @lizan - envoyproxy#23817 (051c119) @WPCode Signed-off-by: Dhi Aurrahman <dio@rockybars.com>
dio
added a commit
to dio/envoy
that referenced
this pull request
Nov 4, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Cherry-picked from: 7ac5336. Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Dhi Aurrahman <dio@rockybars.com>
phlax
pushed a commit
that referenced
this pull request
Nov 4, 2022
…23837) * backport: ci: use host docker gid for envoybuild (#23803) Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Cherry-picked from: 7ac5336. Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Dhi Aurrahman <dio@rockybars.com> * deps: update Ragel (#22635) Commit Message: deps: update Ragel Additional Description: A thread of Ragel and its license has been opened in the Slack channel today. Currently, Ragel is under GPLv2. It is legal to use Ragel as a tool to compile, but we have to compile Ragel in Envoy's building system and there is potential risk of the copyright. The patch updates Ragel to the latest version with MIT license to suppress the concern. Risk Level: Low Testing: N/A Docs Changes: N/A Release Notes: N/A Platform Specific Features: N/A Signed-off-by: Xie Zhihao <zhihao.xie@intel.com> Signed-off-by: Dhi Aurrahman <dio@rockybars.com> * Conflict Signed-off-by: Dhi Aurrahman <dio@rockybars.com> Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Dhi Aurrahman <dio@rockybars.com> Signed-off-by: Xie Zhihao <zhihao.xie@intel.com>
phlax
pushed a commit
to phlax/envoy
that referenced
this pull request
Nov 7, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Ryan Northey <ryan@synca.io>
phlax
pushed a commit
that referenced
this pull request
Nov 8, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Ryan Northey <ryan@synca.io>
phlax
pushed a commit
to phlax/envoy
that referenced
this pull request
Nov 11, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Dario Cillerai <dcillera@redhat.com> Signed-off-by: Ryan Northey <ryan@synca.io>
phlax
pushed a commit
that referenced
this pull request
Nov 15, 2022
Previously `/var/run/docker.sock` is readable/writable inside docker run because group ID of `envoygroup` coincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcing `envoygroup` has host docker group ID. Risk Level: Low Testing: CI Docs Changes: Release Notes: Platform Specific Features: Signed-off-by: Lizan Zhou <lizan@tetrate.io> Signed-off-by: Dario Cillerai <dcillera@redhat.com> Signed-off-by: Ryan Northey <ryan@synca.io>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously
/var/run/docker.sockis readable/writable inside docker run because group ID ofenvoygroupcoincidentally matches host docker group, while it is no longer true during rolling out new image. Fixing that by forcingenvoygrouphas host docker group ID.Risk Level: Low
Testing: CI
Docs Changes:
Release Notes:
Platform Specific Features:
[Optional Runtime guard:]
[Optional Fixes #Issue]
[Optional Fixes commit #PR or SHA]
[Optional Deprecated:]
[Optional API Considerations:]