-
Notifications
You must be signed in to change notification settings - Fork 1.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Copy serviceAccountName to affinity-assistant #3751
Copy serviceAccountName to affinity-assistant #3751
Conversation
When a serviceAccountName is specified on a PipelineRun, all Pods that execute the constituent Tasks run with the specified ServiceAccount. If an Affinity Assistant pod is launched, it should also run with the same ServiceAccount. This ensures that cluster policies apply consistently to Tekton-launched Pods, and it avoids use of the "default" ServiceAccount that is discouraged by some Kubernetes security experts.
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here.
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Hi @ewolak-sq. Thanks for your PR. I'm waiting for a tektoncd member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
/ok-to-test |
The following is the coverage report on the affected files.
|
/test tekton-pipeline-unit-tests |
/test check-pr-has-kind-label |
The following is the coverage report on the affected files.
|
@ewolak-sq: The following test failed, say
Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
Issues go stale after 90d of inactivity. /lifecycle stale Send feedback to tektoncd/plumbing. |
Stale issues rot after 30d of inactivity. /lifecycle rotten Send feedback to tektoncd/plumbing. |
Resolves #3748
Changes
When a serviceAccountName is specified on a PipelineRun, all Pods that
execute the constituent Tasks run with the specified ServiceAccount. If
an Affinity Assistant pod is launched, it should also run with the same
ServiceAccount. This ensures that cluster policies apply consistently to
Tekton-launched Pods, and it avoids use of the "default" ServiceAccount
that is discouraged by some Kubernetes security experts.
/kind bug
Submitter Checklist
These are the criteria that every PR should meet, please check them off as you
review them:
See the contribution guide for more details.
Double check this list of stuff that's easy to miss:
cmd
dir, please updatethe release Task to build and release this image.
Reviewer Notes
If API changes are included, additive changes must be approved by at least two OWNERS and backwards incompatible changes must be approved by more than 50% of the OWNERS, and they must first be added in a backwards compatible way.
Release Notes