Repository navigation
Vouch request: sallyom #4396
sallyom
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
What do you want to work on?
I want to ensure agent harnesses in OpenShell on K8s work well.
Why this change?
I want to add an opt-in
ensure_private_subpathtovolume_mounts[]for non-root applications with strict state directory filesystem permissions and ownership checks. In K8s, volume-mounted directories are often root-owned because kubelet creates them. OpenShell setsfsGrouptoSandbox GIDbut it doesn't change the owner UID. This results in directories that are root-owned and group-writeable.For example, OpenClaw's worker nodes reject any world/group-writeable directories without sticky permissions.
Alternative is an additional pod preparation external to OpenShell that could require elevated permissions or added RBAC.
Checklist
All reactions