From 1e54eb4f6acbb83806e233169714379af2b8a461 Mon Sep 17 00:00:00 2001 From: Dorian Karter Date: Tue, 29 Sep 2026 12:35:06 -0500 Subject: [PATCH] fix: restrict WAL directory init container --- Chart.yaml | 2 +- templates/deployment.yaml | 4 ++++ test/test.sh | 15 +++++++++++++++ 3 files changed, 20 insertions(+), 1 deletion(-) diff --git a/Chart.yaml b/Chart.yaml index cb8ce1d..ab97e6d 100644 --- a/Chart.yaml +++ b/Chart.yaml @@ -1,4 +1,4 @@ apiVersion: v1 name: pgdog -version: v0.80 +version: v0.81 appVersion: "v0.1.58" diff --git a/templates/deployment.yaml b/templates/deployment.yaml index 1a244e9..c0294bf 100644 --- a/templates/deployment.yaml +++ b/templates/deployment.yaml @@ -65,6 +65,10 @@ spec: {{- end }} imagePullPolicy: {{ .Values.image.pullPolicy }} command: ["mkdir", "-p", "/var/lib/pgdog/wal"] + securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: ["ALL"] volumeMounts: - name: wal mountPath: /var/lib/pgdog diff --git a/test/test.sh b/test/test.sh index bed4773..ec4f63d 100755 --- a/test/test.sh +++ b/test/test.sh @@ -66,5 +66,20 @@ else exit 1 fi +# The WAL init container needs its own privilege settings; these cannot be set +# through podSecurityContext or the main container's securityContext. +echo "" +echo "==> Validating WAL init container privilege settings..." +wal_init_security_context=$(helm template test-release "$CHART_DIR" -f "$TEST_DIR/values-statefulset.yaml" \ + | yq -o=json -I=0 'select(.kind == "StatefulSet") | .spec.template.spec.initContainers[] | select(.name == "create-wal-directory") | .securityContext') + +if [ "$wal_init_security_context" = '{"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]}}' ]; then + echo " WAL init container drops capabilities and disallows privilege escalation" +else + echo " FAIL: WAL init container lacks required privilege settings" + echo " Got: $wal_init_security_context" + exit 1 +fi + echo "" echo "==> All tests passed!"