Skip to content

Run spire-agent and spiffe-csi-driver as root and add default "run" subcommand to SPIRE entrypoints#1847

Merged
chez-shanpu merged 1 commit intomainfrom
fix-spire
Feb 27, 2026
Merged

Run spire-agent and spiffe-csi-driver as root and add default "run" subcommand to SPIRE entrypoints#1847
chez-shanpu merged 1 commit intomainfrom
fix-spire

Conversation

@chez-shanpu
Copy link
Contributor

  • spire-agent requires root for Unix domain socket creation and hostNetwork/hostPID access (upstream uses USER 0:0)
  • spiffe-csi-driver requires privileged host filesystem access for volume mounts (upstream has no USER directive)

…ubcommand to SPIRE entrypoints

Signed-off-by: Tomoki Sugiura <tomoki-sugiura@cybozu.co.jp>
@chez-shanpu chez-shanpu requested a review from yokaze February 27, 2026 01:55
Copy link
Contributor

@yokaze yokaze left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chez-shanpu chez-shanpu merged commit 58e9c86 into main Feb 27, 2026
8 checks passed
@chez-shanpu chez-shanpu deleted the fix-spire branch February 27, 2026 02:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants