Run mongodb monitoring and backup agents as non-root user

- We need to modify the read permissions on the secrets and allow
the mongodb-mms-agent to read the credentials.
This commit is contained in:
Muawia Khan 2017-08-15 15:59:08 +02:00
parent e7640feaec
commit 650177c50e
4 changed files with 6 additions and 6 deletions

View File

@ -20,5 +20,5 @@ RUN apt update \
COPY mongodb_backup_agent_entrypoint.bash /
RUN chown -R mongodb-mms-agent:mongodb-mms-agent /etc/mongodb-mms/
VOLUME /etc/mongod/ssl
#USER mongodb-mms-agent - BUG(Krish) Uncomment after tests are complete
USER mongodb-mms-agent
ENTRYPOINT ["/mongodb_backup_agent_entrypoint.bash"]

View File

@ -51,8 +51,8 @@ spec:
- name: mdb-bak-certs
secret:
secretName: mdb-bak-certs
defaultMode: 0400
defaultMode: 0404
- name: cloud-manager-credentials
secret:
secretName: cloud-manager-credentials
defaultMode: 0400
defaultMode: 0404

View File

@ -54,5 +54,5 @@ RUN apt update \
COPY mongodb_mon_agent_entrypoint.bash /
RUN chown -R mongodb-mms-agent:mongodb-mms-agent /etc/mongodb-mms/
VOLUME /etc/mongod/ssl
#USER mongodb-mms-agent - BUG(Krish) Uncomment after tests are complete
USER mongodb-mms-agent
ENTRYPOINT ["/mongodb_mon_agent_entrypoint.bash"]

View File

@ -51,8 +51,8 @@ spec:
- name: mdb-mon-certs
secret:
secretName: mdb-mon-certs
defaultMode: 0400
defaultMode: 0404
- name: cloud-manager-credentials
secret:
secretName: cloud-manager-credentials
defaultMode: 0400
defaultMode: 0404