Skip to content

fix: restrict WAL directory init container - #142

Merged
levkk merged 1 commit into
pgdogdev:mainfrom
dkarter:fix/wal-init-restricted-security
Sep 29, 2026
Merged

levkk merged 1 commit into
pgdogdev:mainfrom
dkarter:fix/wal-init-restricted-security

Conversation

@dkarter

@dkarter dkarter commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

With statefulSet.walPvc.enabled, the chart adds a create-wal-directory init container. Kubernetes rejects this pod under the Restricted Pod Security policy because that container does not disable privilege escalation or drop its capabilities. The main PgDog container’s security context does not apply to the init container.

When we try to enable 2pc durable storage we're getting:

Create Pod pgdog-0 in StatefulSet pgdog failed error: pods "pgdog-0" is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "create-wal-directory" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "create-wal-directory" must set securityContext.capabilities.drop=["ALL"])

That's due to our stricter PodSecurity security policy.

Summary of Changes

  • Set allowPrivilegeEscalation: false and drop all capabilities on the WAL init container.
  • Add a rendering test for those fields and bump the chart version to v0.81.

Testing

./test/test.sh passes. To check the fix manually, render the chart with test/values-statefulset.yaml and inspect spec.template.spec.initContainers[name=create-wal-directory].securityContext. Deploy to a namespace enforcing Restricted Pod Security with a non-root pod security context and confirm the StatefulSet can create its pods.

Dependencies/Special Considerations

This changes only the WAL init container; callers still need to set their pod-level non-root user and seccomp settings to meet the rest of the Restricted policy.

@dkarter
dkarter marked this pull request as ready for review September 29, 2026 17:37
Comment thread test/test.sh

# The WAL init container needs its own privilege settings; these cannot be set
# through podSecurityContext or the main container's securityContext.
echo ""

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should put an instruction into AGENTS.md to stop doing this. We already validate the yaml with kubeconform.

@levkk
levkk merged commit a0ae99a into pgdogdev:main Sep 29, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants