-
Notifications
You must be signed in to change notification settings - Fork 1.1k
fix(security): Storage & Memory limits should be enforced in test/gha-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. #5261
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…sample file samples/juicefs/read_job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
Signed-off-by: JiGuoDing <485204300@qq.com>
…-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #5261 +/- ##
=======================================
Coverage 56.70% 56.70%
=======================================
Files 440 440
Lines 30369 30369
=======================================
Hits 17220 17220
Misses 11537 11537
Partials 1612 1612 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
yangyuliufeng
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
samples/jindo/job.yaml
Outdated
| resources: | ||
| limits: | ||
| memory: "64Mi" | ||
| ephemeral-storage: "512Mi" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I suggest setting the memory limits to 512Mi and storage limits to 5Gi.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the suggestion—I’ll apply those limits.
…/jindo/job.yaml Signed-off-by: JiGuoDing <485204300@qq.com>
|
RongGu
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/lgtm
/approve
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: RongGu, yangyuliufeng The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
…-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. (fluid-cloudnative#5261) * fix(security): Service account permissions should be restricted. Add sample file samples/juicefs/read_job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com> * fix: add memory limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> * fix: add storage limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> * fix: alter storage limit to comply with security policy Signed-off-by: JiGuoDing <485204300@qq.com> * fix(security): Storage & Memory limits should be enforced in test/gha-e2e/jindo/job.yaml. Add a sample file samples/jindo/job.yaml. Signed-off-by: JiGuoDing <485204300@qq.com> * fix(security): enforce 512Mi memory and 5Gi storage limits in samples/jindo/job.yaml Signed-off-by: JiGuoDing <485204300@qq.com> --------- Signed-off-by: JiGuoDing <485204300@qq.com>



Ⅰ. Describe what this PR does
This PR addresses the security finding “Memory & Storage limits should be enforced” by introducing a new hardened sample Job manifest samples/jindo/job.yaml.
The sample demonstrates how to securely configure a Kubernetes Job with constrained resource usage by explicitly setting:
Ⅱ. Does this pull request fix one issue?
fixes #XXXX
Ⅲ. List the added test cases (unit test/integration test) if any, please explain if no tests are needed.
No automated tests are required.
Ⅳ. Describe how to verify it
Ⅴ. Special notes for reviews