-
Notifications
You must be signed in to change notification settings - Fork 1.1k
fix(security): Storage & Memory limits should be enforced in test/gha-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. #5261
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…sample file samples/juicefs/read_job.yaml. Signed-off-by: JiGuoDing <[email protected]>
Signed-off-by: JiGuoDing <[email protected]>
Signed-off-by: JiGuoDing <[email protected]>
Signed-off-by: JiGuoDing <[email protected]>
…-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. Signed-off-by: JiGuoDing <[email protected]>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #5261 +/- ##
=======================================
Coverage 56.70% 56.70%
=======================================
Files 440 440
Lines 30369 30369
=======================================
Hits 17220 17220
Misses 11537 11537
Partials 1612 1612 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
samples/jindo/job.yaml
Outdated
resources: | ||
limits: | ||
memory: "64Mi" | ||
ephemeral-storage: "512Mi" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I suggest setting the memory limits to 512Mi and storage limits to 5Gi.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the suggestion—I’ll apply those limits.
…/jindo/job.yaml Signed-off-by: JiGuoDing <[email protected]>
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: RongGu, yangyuliufeng The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Ⅰ. Describe what this PR does
This PR addresses the security finding “Memory & Storage limits should be enforced” by introducing a new hardened sample Job manifest samples/jindo/job.yaml.
The sample demonstrates how to securely configure a Kubernetes Job with constrained resource usage by explicitly setting:
Ⅱ. Does this pull request fix one issue?
fixes #XXXX
Ⅲ. List the added test cases (unit test/integration test) if any, please explain if no tests are needed.
No automated tests are required.
Ⅳ. Describe how to verify it
Ⅴ. Special notes for reviews