splunk / splunk-operator

Splunk Operator for Kubernetes
Other
210 stars 115 forks source link

Splunk Operator: Containers Need Readonly Root Filesystem #1323

Open thormanrd opened 7 months ago

thormanrd commented 7 months ago

Please select the type of request

Enhancement

Tell us more

Describe the request

Expected behavior

Splunk setup on K8S

Reproduction/Testing steps

K8s collector data(optional)

Additional context(optional)

vivekr-splunk commented 7 months ago

@thormanrd, we're collaborating with our internal team and product department to assess the feasibility of prioritizing this feature change. The change is necessary in Splunk Ansible, and redesigning it entails eliminating the use of sudo. We'll provide you with an update on the timelines shortly.

yaroslav-nakonechnikov commented 7 months ago

@thormanrd why this is here and not in https://github.com/splunk/docker-splunk ?

thormanrd commented 7 months ago

@yaroslav-nakonechnikov because the operator has it's own issues for read-only settings and then deploys containers with issues.

yaroslav-nakonechnikov commented 7 months ago

i've re-read description, and it is still not clear which container is affected. for splunk-operator image? or just splunk? for splunk - root cause is docker-splunk project, and creating ticket here won't help in any way... just because i already struggle a lot with that project.

and if you have access to splunk support - please, also raise ticket there, for reference. otherwise i have a strong feeling that all issues in gh are considered as low priority.