The annotate namespaces Job of the operator Helm chart can not start: runAsNonRoot without runAsUser
Summary
The <release>-annotate-namespaces Job of the operator Helm chart, the pre-install/pre-upgrade
hook that labels the allowed namespaces, never starts when allowedNamespaces is set. Its Pod is
rejected by the kubelet with:
Error: container has runAsNonRoot and image has non-numeric user (stackgres), cannot verify user is non-rootstackgres-k8s/install/helm/stackgres-operator/templates/label-allowed-namespaces.yaml sets
runAsNonRoot: true on the Pod security context but no runAsUser:
securityContext:
{{- if or (not (.Capabilities.APIVersions.Has "project.openshift.io/v1")) .Values.developer.disableArbitraryUser }}
runAsNonRoot: true
{{- end }}The USER of the kubectl image the Job runs is the name stackgres, not a numeric id
(docker inspect --format '{{ .Config.User }}' prints stackgres, and the user is uid=1000).
The kubelet does not resolve names from the image at admission time, so with runAsNonRoot: true
and no runAsUser it can not prove the container is not root and refuses to start it.
The sibling templates that run the very same image already set the id explicitly:
tests/test-operator.yaml uses runAsUser: 1000, runAsGroup: 1000 and fsGroup: 1000 under the
same condition. This template was simply left behind.
Impact
- Installing or upgrading the operator chart with
allowedNamespacesset never completes: thepre-install/pre-upgradehook Job backs off forever and Helm waits for it. - Reported upgrading from 1.18.8 to 1.19.1, but it applies to any version whose chart carries this template and to a plain install as well.
- The allowed namespaces are left without the
stackgres.io/scopelabel, so the operator does not pick them up. stackgres-k8s/install/helm/stackgres-cluster/templates/cluster-restart-job.yamlhas the same defect for itspost-upgradeJob, which runs the same image withrunAsNonRoot: trueand norunAsUser.
Proposed resolution
Set runAsUser, runAsGroup and fsGroup to 1000 next to runAsNonRoot: true in both templates,
keeping them inside the condition that leaves the security context to the SCC on OpenShift, exactly
as tests/test-operator.yaml already does for the same image.