RC-9-A: Bugfix
release-tag / release-image (push) Successful in 4m41s

This commit is contained in:
2026-08-11 20:33:43 +02:00
parent 1f61989c2d
commit eefe6dd415
4 changed files with 64 additions and 8 deletions
+11 -8
View File
@@ -210,10 +210,10 @@ func (d *DockerClient) CreateWorker(ctx context.Context, c WorkerContainerConfig
name := url.QueryEscape(c.Name)
body := map[string]any{
"Image": c.Image,
// Named Docker volumes are root-owned when first mounted. Managed workers
// therefore run uid 0 only inside their own locked-down container so they
// can create the 0600 identity file. They receive no Docker socket, all
// Linux capabilities are dropped and the image root filesystem is read-only.
// Named Docker volumes are root-owned when first mounted, and identities
// created by older releases may be owned by a different UID. The dedicated
// worker image starts as uid 0 only for its tiny ownership-normalization
// entrypoint and immediately drops to the unprivileged app user.
"User": "0:0",
"Cmd": []string{"-url", c.GameURL, "-identity", "/identity/identity.json", "-non-interactive", "-quiet", "-task", c.TaskID, "-beacon-path", c.BeaconPath},
"Env": []string{
@@ -228,10 +228,13 @@ func (d *DockerClient) CreateWorker(ctx context.Context, c WorkerContainerConfig
"NetworkMode": c.Network,
"ReadonlyRootfs": true,
"CapDrop": []string{"ALL"},
"SecurityOpt": []string{"no-new-privileges"},
"PidsLimit": 128,
"Memory": 256 * 1024 * 1024,
"NanoCpus": int64(1_000_000_000),
// Bootstrap-only capabilities: the image entrypoint fixes ownership of
// /identity and then su-exec permanently switches to uid/gid app.
"CapAdd": []string{"CHOWN", "DAC_OVERRIDE", "SETUID", "SETGID"},
"SecurityOpt": []string{"no-new-privileges"},
"PidsLimit": 128,
"Memory": 256 * 1024 * 1024,
"NanoCpus": int64(1_000_000_000),
},
}
// A dedicated worker image already declares /app/neuralhunt-client as its