-
Notifications
You must be signed in to change notification settings - Fork 8
🐛 Fix security context for job-queue-service #42
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
9774a19
2d56e24
84142b6
0fa0f9f
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -38,21 +38,20 @@ spec: | |
| spec: | ||
| terminationGracePeriodSeconds: 60 | ||
| serviceAccountName: harbor-orchestrator | ||
| securityContext: | ||
| fsGroup: 1001 | ||
| containers: | ||
| - image: ghcr.io/redhat-et/coding_agent_bench:v0.2.5 | ||
| name: job-queue | ||
| command: ["/bin/sh", "-c"] | ||
| args: | ||
| - | | ||
| mkdir -p ~/.ssh && \ | ||
| ([ -f /app/data/nebius-ssh-key ] || ssh-keygen -t ed25519 -f /app/data/nebius-ssh-key -N "" -q) && \ | ||
| chmod 600 /app/data/nebius-ssh-key && \ | ||
| if [ ! -f /app/data/nebius-ssh-key ]; then | ||
| ssh-keygen -t ed25519 -f /app/data/nebius-ssh-key -N "" -q || exit 1 | ||
| fi | ||
| test -r /app/data/nebius-ssh-key || exit 1 | ||
|
Comment on lines
+47
to
+50
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🩺 Stability & Availability | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: sed -n '35,100p' deploy/job-queue-service.yml
rg -n 'NEBIUS_SSH_(PRIVATE|PUBLIC)_KEY_PATH|NebiusInstanceManager|ssh_public|public_key|private_key' . --glob '!deploy/job-queue-service.yml'Repository: redhat-et/coding_agent_bench Length of output: 3633 Validate the complete SSH key pair. If Derive the public key from the validated private key and atomically replace the 🤖 Prompt for AI Agents |
||
| exec env \ | ||
| NEBIUS_SSH_PUBLIC_KEY_PATH=/app/data/nebius-ssh-key.pub \ | ||
| NEBIUS_SSH_PRIVATE_KEY_PATH=/app/data/nebius-ssh-key \ | ||
| uv run uvicorn coding_agent_bench.api:app --host 0.0.0.0 --port 8443 \ | ||
| uv run --no-sync uvicorn coding_agent_bench.api:app --host 0.0.0.0 --port 8443 \ | ||
| --ssl-certfile /etc/job-queue/tls/tls.crt \ | ||
| --ssl-keyfile /etc/job-queue/tls/tls.key | ||
| resources: | ||
|
|
@@ -71,6 +70,10 @@ spec: | |
| seccompProfile: | ||
| type: RuntimeDefault | ||
| env: | ||
| - name: HOME | ||
| value: /tmp | ||
| - name: UV_CACHE_DIR | ||
| value: /tmp/uv-cache | ||
| - name: JOB_STORE_PATH | ||
| value: /app/data/jobs.db | ||
| envFrom: | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: redhat-et/coding_agent_bench
Length of output: 22159
🤖 get_repo_knowledge executed:
get_repo_knowledge redhat-et/coding_agent_bench /tmp/coderabbit-repo-knowledge/redhat-et-coding-agent-bench-fa0c0d0c/conventionsLength of output: 413
🏁 Script executed:
Repository: redhat-et/coding_agent_bench
Length of output: 19316
🏁 Script executed:
Repository: redhat-et/coding_agent_bench
Length of output: 11799
Ensure the fresh PVC is writable by the pod’s non-root user.
job-queue-pvcuses thegp3storage class and mounts at/app/data. The pod definesrunAsNonRootbut nofsGroupor explicitrunAsUser. If the provisioned filesystem is root-owned without write permission for the runtime UID,ssh-keygenfails and the container exits before the service starts. Provide an ownership or permission mechanism through the OpenShift deployment, or restore an appropriatefsGroup.🤖 Prompt for AI Agents