tektoncd / dashboard

A dashboard for Tekton!
Apache License 2.0
863 stars 258 forks source link

Set readOnlyRootFileSystem to improve security posture #3468

Closed AlanGreene closed 1 week ago

AlanGreene commented 1 week ago

Changes

Similar change already made in Chains, and PRs open for Pipelines and Triggers /kind misc

Submitter Checklist

As the author of this PR, please check off the items in this checklist:

Release Notes

NONE
tekton-robot commented 1 week ago

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: To complete the pull request process, please ask for approval from alangreene after the PR has been reviewed.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files: - **[OWNERS](https://github.com/tektoncd/dashboard/blob/main/OWNERS)** Approvers can indicate their approval by writing `/approve` in a comment Approvers can cancel approval by writing `/approve cancel` in a comment
AlanGreene commented 1 week ago

Need to check how this impacts use of nginx config templating in https://github.com/alangreene/dashboard-next. May need to mount a volume for use by some of the config scripts at startup. /hold