Skip to content

Conversation

@JiGuoDing
Copy link
Collaborator

Ⅰ. Describe what this PR does

This PR addresses the security finding “Service account permissions should be restricted” by introducing a new hardened sample Job manifest samples/juicefs/read_job.yaml.

The sample demonstrates how to securely configure a Kubernetes Job that reads from a PVC without requiring Kubernetes API access, by explicitly setting:

automountServiceAccountToken: false

Ⅱ. Does this pull request fix one issue?

fixes #XXXX

Ⅲ. List the added test cases (unit test/integration test) if any, please explain if no tests are needed.

No automated tests are required.

Ⅳ. Describe how to verify it

Ⅴ. Special notes for reviews

…sample file samples/juicefs/read_job.yaml.

Signed-off-by: JiGuoDing <485204300@qq.com>
@codecov
Copy link

codecov bot commented Sep 17, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 55.50%. Comparing base (8236f7a) to head (70f449d).
⚠️ Report is 11 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #5242      +/-   ##
==========================================
- Coverage   55.51%   55.50%   -0.01%     
==========================================
  Files         443      443              
  Lines       30382    30438      +56     
==========================================
+ Hits        16867    16896      +29     
- Misses      11962    11978      +16     
- Partials     1553     1564      +11     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@RongGu
Copy link
Member

RongGu commented Sep 18, 2025

/lgtm

Signed-off-by: JiGuoDing <485204300@qq.com>
@fluid-e2e-bot fluid-e2e-bot bot removed the lgtm label Sep 18, 2025
Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
@sonarqubecloud
Copy link

Copy link
Collaborator

@cheyang cheyang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm
/approve

@RongGu RongGu merged commit 21f9325 into fluid-cloudnative:master Sep 22, 2025
15 of 16 checks passed
@fluid-e2e-bot fluid-e2e-bot bot added the lgtm label Sep 24, 2025
@fluid-e2e-bot
Copy link

fluid-e2e-bot bot commented Sep 24, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: cheyang

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

Pikabooboo pushed a commit to Pikabooboo/fluid that referenced this pull request Sep 25, 2025
…sample file samples/juicefs/read_job.yaml. (fluid-cloudnative#5242)

* fix(security): Service account permissions should be restricted. Add sample file samples/juicefs/read_job.yaml.

Signed-off-by: JiGuoDing <485204300@qq.com>

* fix: add memory limit to comply with security policy

Signed-off-by: JiGuoDing <485204300@qq.com>

* fix: add storage limit to comply with security policy

Signed-off-by: JiGuoDing <485204300@qq.com>

* fix: alter storage limit to comply with security policy

Signed-off-by: JiGuoDing <485204300@qq.com>

---------

Signed-off-by: JiGuoDing <485204300@qq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants