fix: hermes-webui container start failure due to PodSecurity restricted policy
- Updated pod.spec.securityContext and all container/initContainer securityContext to be fully compliant with restricted:latest (runAsNonRoot: true, allowPrivilegeEscalation: false, runAsUser: 1000, capabilities drop ALL, seccomp RuntimeDefault, fsGroup) - Changed initContainer from root chown to non-root mkdir/chmod relying on fsGroup (avoids PSA violation) - Updated default model to grok-4.20-0309-reasoning (per xAI switch note) - Added automountServiceAccountToken: false and imagePullPolicy for best practices (matches openclaw deployment pattern) - hermes-webui now runs as non-root with WANTED_UID matching This should resolve the container not starting. Leave PR open for review before merge.
This commit is contained in:
parent
560f5b76cf
commit
d2f011956e
2 changed files with 30 additions and 10 deletions
|
|
@ -6,7 +6,7 @@ metadata:
|
||||||
data:
|
data:
|
||||||
config.yaml: |
|
config.yaml: |
|
||||||
model:
|
model:
|
||||||
default: grok-4-1-fast
|
default: grok-4.20-0309-reasoning
|
||||||
provider: xai
|
provider: xai
|
||||||
base_url: https://api.x.ai/v1
|
base_url: https://api.x.ai/v1
|
||||||
providers:
|
providers:
|
||||||
|
|
|
||||||
|
|
@ -13,33 +13,50 @@ spec:
|
||||||
labels:
|
labels:
|
||||||
app: hermes-agent
|
app: hermes-agent
|
||||||
spec:
|
spec:
|
||||||
|
automountServiceAccountToken: false
|
||||||
securityContext:
|
securityContext:
|
||||||
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
runAsGroup: 1000
|
runAsGroup: 1000
|
||||||
fsGroup: 1000
|
fsGroup: 1000
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
initContainers:
|
initContainers:
|
||||||
- name: fix-webui-perms
|
- name: fix-webui-perms
|
||||||
image: busybox:1.36
|
image: busybox:1.37
|
||||||
|
imagePullPolicy: IfNotPresent
|
||||||
securityContext:
|
securityContext:
|
||||||
runAsUser: 0
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
runAsGroup: 1000
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
capabilities:
|
||||||
|
drop:
|
||||||
|
- ALL
|
||||||
|
seccompProfile:
|
||||||
|
type: RuntimeDefault
|
||||||
command:
|
command:
|
||||||
- sh
|
- sh
|
||||||
- -c
|
- -c
|
||||||
args:
|
args:
|
||||||
- |
|
- |
|
||||||
chown -R 1000:1000 /data
|
mkdir -p /data/.hermes/webui /data/.cache /data/.config /data/bin
|
||||||
chmod -R g+rwX,o-rwx /data
|
chmod -R g+rwX,o-rwx /data
|
||||||
|
echo "✅ Hermes data permissions fixed (non-root with fsGroup)"
|
||||||
volumeMounts:
|
volumeMounts:
|
||||||
- name: hermes-data
|
- name: hermes-data
|
||||||
mountPath: /data
|
mountPath: /data
|
||||||
containers:
|
containers:
|
||||||
- name: hermes-agent
|
- name: hermes-agent
|
||||||
securityContext:
|
securityContext:
|
||||||
allowPrivilegeEscalation: true
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
runAsGroup: 1000
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
runAsUser: 1000
|
|
||||||
runAsGroup: 1000
|
|
||||||
seccompProfile:
|
seccompProfile:
|
||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
image: nousresearch/hermes-agent:latest
|
image: nousresearch/hermes-agent:latest
|
||||||
|
|
@ -104,7 +121,7 @@ spec:
|
||||||
value: xai
|
value: xai
|
||||||
|
|
||||||
- name: HERMES_MODEL
|
- name: HERMES_MODEL
|
||||||
value: grok-4.1-fast
|
value: grok-4.20-0309-reasoning
|
||||||
|
|
||||||
- name: OPENAI_API_KEY
|
- name: OPENAI_API_KEY
|
||||||
value: "dummy" # vLLM ignores this
|
value: "dummy" # vLLM ignores this
|
||||||
|
|
@ -168,11 +185,14 @@ spec:
|
||||||
memory: 512Mi
|
memory: 512Mi
|
||||||
cpu: "500m"
|
cpu: "500m"
|
||||||
securityContext:
|
securityContext:
|
||||||
allowPrivilegeEscalation: true
|
runAsNonRoot: true
|
||||||
|
runAsUser: 1000
|
||||||
|
runAsGroup: 1000
|
||||||
|
allowPrivilegeEscalation: false
|
||||||
|
readOnlyRootFilesystem: false
|
||||||
capabilities:
|
capabilities:
|
||||||
drop:
|
drop:
|
||||||
- ALL
|
- ALL
|
||||||
runAsUser: 0
|
|
||||||
seccompProfile:
|
seccompProfile:
|
||||||
type: RuntimeDefault
|
type: RuntimeDefault
|
||||||
volumes:
|
volumes:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue