Skip to content

Reduce permissions on GKM containers #100

@Billy99

Description

@Billy99

When moving from using CSI Agent to mount extracted cache to using PVCs, GKM under went a major rewrite. One of the motivations for the move to PVCs was to remove the need for GKM to access the host node's filesystem and thus remove the higher privileges needed to do so. Revisit what permissions are required for GKM to run.

Note: There is work in MCV to move to https://github.com/jaypipes/ghw, which will allow MCV to detect GPU devices without root privileges. This will be needed to reduce GKMs permissions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions