Fix nats-bootstrap: run from /tmp so the nats CLI works under readOnlyRootFS
The nats-bootstrap PostSync Job failed at deploy time with "could not load schema ... stat .: permission denied". The nats CLI stats its working directory when loading response-validation schemas, and under the Job's readOnlyRootFilesystem + runAsUser 1000 the image's default WORKDIR is not accessible. Set workingDir: /tmp (the writable emptyDir already mounted for HOME) so the CLI can stat/operate. Verified against the live cluster: a nats-box pod with the exact restrictive securityContext + workingDir: /tmp runs `nats stream info` cleanly. Without this the PostSync hook never completes, so the logging-logging app stays OutOfSync (the LOGS stream/consumers persist in JetStream once created, so log flow is unaffected, but GitOps convergence is blocked). Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
This commit is contained in:
@@ -59,6 +59,11 @@ spec:
|
||||
containers:
|
||||
- name: nats-bootstrap
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/dockerhub/natsio/nats-box:0.18.0
|
||||
# nats CLI stats the working directory when loading its response
|
||||
# schemas; under readOnlyRootFilesystem + runAsUser 1000 the image's
|
||||
# default WORKDIR is not accessible ("stat .: permission denied"), so
|
||||
# run from the writable /tmp emptyDir.
|
||||
workingDir: /tmp
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
|
||||
Reference in New Issue
Block a user