Fix nats-bootstrap: run from /tmp so the nats CLI works under readOnlyRootFS #311

Merged
benvin merged 1 commits from benvin/logging-deploy-fixes-3 into main 2026-07-30 00:11:16 +10:00

1 Commits

Author SHA1 Message Date
unkinben d9eb13c3e6 Fix nats-bootstrap: run from /tmp so the nats CLI works under readOnlyRootFS
ci/woodpecker/pr/vector-test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/kubeconform Pipeline was successful
The nats-bootstrap PostSync Job failed at deploy time with
"could not load schema ... stat .: permission denied". The nats CLI stats its
working directory when loading response-validation schemas, and under the Job's
readOnlyRootFilesystem + runAsUser 1000 the image's default WORKDIR is not
accessible. Set workingDir: /tmp (the writable emptyDir already mounted for
HOME) so the CLI can stat/operate. Verified against the live cluster: a nats-box
pod with the exact restrictive securityContext + workingDir: /tmp runs
`nats stream info` cleanly.

Without this the PostSync hook never completes, so the logging-logging app
stays OutOfSync (the LOGS stream/consumers persist in JetStream once created, so
log flow is unaffected, but GitOps convergence is blocked).

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-29 22:41:34 +10:00