-
Notifications
You must be signed in to change notification settings - Fork 60
[release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds #186
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release-4.6] Bug 1895093: Do not mount /etc/pki/ca-trust in builds #186
Conversation
`/etc/pki/ca-trust` contains the system trust stores for a wide array of applications. Making this a mount point in buildah causes the original data in the base image to overlayed by the contents in the build container. As a result, `/etc/pki/ca-trust` cannot be altered unless another layer is added to the image being built via a COPY or ADD instruction. This will revert the mount of `/etc/pki/ca-trust`, thereby removing the ability of builds to use the cluster trust bundle. This capability will be restored in a future OpenShift release as an opt-in enhancement.
|
@openshift-cherrypick-robot: Bugzilla bug 1891759 has been cloned as Bugzilla bug 1895093. Retitling PR to link against new bug. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
@openshift-cherrypick-robot: This pull request references Bugzilla bug 1895093, which is invalid:
Comment DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/assign @bparees @adambkaplan 's disablement of the release image breaking change while @coreydaley works on the new opt-in solution just merged into 4.7/master and here is the 4.6.z cherry pick (Adam's out for the rest of today if you want this approved etc. before tomorrow) /lgtm |
|
/approve let's make sure DPTP knows this is coming since this will get us back to a "good" state for building image-registry/etc, until the opt-in feature is complete. cc @dmage |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: bparees, gabemontero, openshift-cherrypick-robot The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
I did communicate this to @stevekuznetsov |
toward the bottom of this thread: https://coreos.slack.com/archives/CBN38N3MW/p1604591017248200 |
awesome, thank you! |
|
/bugzilla refresh Recalculating validity in case the underlying Bugzilla bug has changed. |
|
@openshift-bot: This pull request references Bugzilla bug 1895093, which is invalid:
Comment DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/retest Please review the full test history for this PR and help us cut down flakes. |
1 similar comment
|
/retest Please review the full test history for this PR and help us cut down flakes. |
|
/bugzilla refresh |
|
@adambkaplan: This pull request references Bugzilla bug 1895093, which is valid. The bug has been moved to the POST state. The bug has been updated to refer to the pull request using the external bug tracker. 6 validation(s) were run on this bug
DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
Patch manager note - this fixes an urgent regression in builds that impacts the ability of teams to build images on CI. |
|
@openshift-cherrypick-robot: All pull requests linked via external trackers have merged: Bugzilla bug 1895093 has been moved to the MODIFIED state. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
This is an automated cherry-pick of #185
/assign adambkaplan