Merge pull request 'Harden kea socket dir to 0750 (fix remaining CrashLoopBackOff)' (#4) from benvin/fix-socket-dir-perms into main
ci/woodpecker/tag/docker Pipeline was successful

Reviewed-on: #4
This commit was merged in pull request #4.
This commit is contained in:
2026-08-08 22:13:30 +10:00
2 changed files with 14 additions and 0 deletions
+2
View File
@@ -35,6 +35,7 @@ func EntrypointDHCP4() string {
set -e
ORD="${HOSTNAME##*-}"
mkdir -p %[1]s
chmod 0750 %[1]s
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
exec %[5]s -c %[4]s
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
@@ -45,6 +46,7 @@ func EntrypointCtrlAgent() string {
return fmt.Sprintf(`#!/bin/sh
set -e
mkdir -p %[1]s
chmod 0750 %[1]s
cp %[2]s/kea-ctrl-agent.conf %[3]s
exec %[4]s -c %[3]s
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
+12
View File
@@ -237,6 +237,18 @@ func TestRenderCtrlAgent(t *testing.T) {
}
}
func TestEntrypointsHardenSocketDir(t *testing.T) {
// Kea 2.6+ rejects a socket dir "more relaxed than 750"; the emptyDir mount
// defaults to 0777, so the entrypoints must chmod it before exec'ing kea.
want := "chmod 0750 " + RunDir
if ep := EntrypointDHCP4(); !strings.Contains(ep, want) {
t.Errorf("dhcp4 entrypoint must %q, got:\n%s", want, ep)
}
if ep := EntrypointCtrlAgent(); !strings.Contains(ep, want) {
t.Errorf("ctrl-agent entrypoint must %q, got:\n%s", want, ep)
}
}
func TestControlSocketPathAllowedByKea(t *testing.T) {
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)