Compare commits

2 Commits

Author SHA1 Message Date
OpenCode Assistant
673d0346f4 Add RoleBinding for calibre anyuid SCC
- Bind calibre-sa to anyuid SecurityContextConstraints
- Enables secure non-root execution for LinuxServer containers
- Maintains production security while ensuring container compatibility
- Fixes supplementary group issues with s6-overlay
2026-01-19 00:40:27 +11:00
a523c6ab33 Merge pull request 'fix: remove restrictive securityContext for s6 compatibility' (#1) from fix-calibre-permissions into main
Reviewed-on: #1
2026-01-18 05:01:16 +00:00

View File

@@ -0,0 +1,18 @@
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: calibre-anyuid-working
namespace: calibre
labels:
app: calibre
app.kubernetes.io/instance: calibre
type: third-party
subjects:
- kind: ServiceAccount
name: calibre-sa
namespace: calibre
roleRef:
kind: ClusterRole
name: anyuid-scc-user
apiGroup: rbac.authorization.k8s.io