Skip to content

Enable the ability to set readOnlyRootFilesystem: false #9504

@calumreesmmt

Description

@calumreesmmt

As part of a security policy audit, we've noticed that you are unable to set the root file system of the ingress nginx containers to ReadOnly. Here's some links for further context:
#6256
https://github.com/mspnp/aks-baseline-regulated/issues/10

One user has mentioned .ASP Net containers needing access to the file system and to overcome this it's possible to create a separate volume mount for the application to use, instead of it using the root file system.

Is it possible to implement the ability to have a read only file system?

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-kindIndicates a PR lacks a `kind/foo` label and requires one.needs-priorityneeds-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

    Type

    No type

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions