forseti-security / helm-charts

Apache License 2.0
8 stars 11 forks source link

Forseti GKE End2End gke master 1.14.10-gke.27 - proxy sql config.json failed: permission denied": unknown #72

Open exenin opened 4 years ago

exenin commented 4 years ago

Warning Failed 13s (x2 over 14s) kubelet, gke-forseti-cluster-default-node-pool-64338854-2rf4 Error: failed to start container "cloudsql-proxy": Error response from daemon: OCI runtime create failed: container_l inux.go:345: starting container process caused "chdir to cwd (\"/home/nonroot\") set in config.json failed: permission denied": unknown

according to this, something changed to allowe security by default but also breaks sql proxy https://github.com/GoogleCloudPlatform/cloudsql-proxy/issues/385

editing the cloudsql-proxy deploy and changing the runAsUser

from runAsUser: 2 to runAsUser: 65532

seems to fix it