Build without filesystem access so the image starts under a read-only root #2

Merged
james merged 1 commit from no-fs-access into main 2026-10-02 22:11:41 +00:00
Owner

v0.1.1 crash-loops on the cluster: Coraza checks at startup that it can write a temp directory, and the Deployment runs with readOnlyRootFilesystem and no /tmp:

waf: load CRS: filesystem access check: create file: open /tmp/checkfsfile...: read-only file system. Use 'no_fs_access' build tag, if not available

Change

Build, test and vet with Coraza's no_fs_access tag (Makefile TAGS, Dockerfile). CRS is embedded and request bodies are scored in memory, so nothing needs the filesystem. The training log is Centinela's own writer and is unaffected.

Verification

  • Reproduced the failure locally by pointing TMPDIR at an unwritable directory; with the tag the same binary starts and scores requests, including a 120 KB body.
  • New test TestLoadsWithoutWritableTmp covers this (runs under the tag, which make test now uses).
  • centinela-eval -backend none gives identical CRS scores at PL1-4 with and without the tag.
  • make vet, make build, make test pass.

Relation to gitops-infra #402

#402 mounts an emptyDir at /tmp, which also fixes the crash. With this change the image no longer needs it; either is sufficient on its own.

v0.1.1 crash-loops on the cluster: Coraza checks at startup that it can write a temp directory, and the Deployment runs with `readOnlyRootFilesystem` and no `/tmp`: ``` waf: load CRS: filesystem access check: create file: open /tmp/checkfsfile...: read-only file system. Use 'no_fs_access' build tag, if not available ``` ## Change Build, test and vet with Coraza's `no_fs_access` tag (Makefile `TAGS`, Dockerfile). CRS is embedded and request bodies are scored in memory, so nothing needs the filesystem. The training log is Centinela's own writer and is unaffected. ## Verification - Reproduced the failure locally by pointing `TMPDIR` at an unwritable directory; with the tag the same binary starts and scores requests, including a 120 KB body. - New test `TestLoadsWithoutWritableTmp` covers this (runs under the tag, which `make test` now uses). - `centinela-eval -backend none` gives identical CRS scores at PL1-4 with and without the tag. - `make vet`, `make build`, `make test` pass. ## Relation to gitops-infra #402 #402 mounts an emptyDir at `/tmp`, which also fixes the crash. With this change the image no longer needs it; either is sufficient on its own.
Build without filesystem access so the image starts under a read-only root
All checks were successful
security-scan / security-scan (pull_request) Successful in 1m15s
test / go (pull_request) Successful in 8m29s
a2477b34a2
Coraza checks at startup that it can write a temp directory and exits if
it cannot. The cluster Deployment sets readOnlyRootFilesystem with no
/tmp, so v0.1.1 crash-looped with "filesystem access check: create file:
open /tmp/checkfsfile...: read-only file system".

CRS is embedded and bodies are scored in memory, so nothing needs the
filesystem: build, test and vet with the no_fs_access tag. CRS scores on
the eval set are identical with and without it.

🔎 ojo scan results

Severity Count
🟢 LOW 1
Details (1)
Type Severity ID/Rule Location Description
misconfig 🟢 LOW dockerfile-no-healthcheck Dockerfile:1 image has no HEALTHCHECK
<!-- ojo-scan-summary --> ### 🔎 ojo scan results | Severity | Count | |---|---| | 🟢 LOW | 1 | <details><summary>Details (1)</summary> | Type | Severity | ID/Rule | Location | Description | |---|---|---|---|---| | misconfig | 🟢 LOW | dockerfile-no-healthcheck | <a href="https://git.colibrisec.org/ColibriSec/centinela/src/commit/a2477b34a2dc0c05c46368262aa8a7267f565f50/Dockerfile#L1" target="_blank" rel="noopener noreferrer">Dockerfile:1</a> | image has no HEALTHCHECK | </details>
james merged commit 1cf2ca8637 into main 2026-10-02 22:11:41 +00:00
james deleted branch no-fs-access 2026-10-02 22:11:41 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
ColibriSec/centinela!2
No description provided.