fix: hermes-webui container start failure due to PodSecurity restricted policy
- Updated pod.spec.securityContext and all container/initContainer securityContext to be fully compliant with restricted:latest (runAsNonRoot: true, allowPrivilegeEscalation: false, runAsUser: 1000, capabilities drop ALL, seccomp RuntimeDefault, fsGroup) - Changed initContainer from root chown to non-root mkdir/chmod relying on fsGroup (avoids PSA violation) - Updated default model to grok-4.20-0309-reasoning (per xAI switch note) - Added automountServiceAccountToken: false and imagePullPolicy for best practices (matches openclaw deployment pattern) - hermes-webui now runs as non-root with WANTED_UID matching This should resolve the container not starting. Leave PR open for review before merge.
This commit is contained in:
parent
560f5b76cf
commit
d2f011956e
2 changed files with 30 additions and 10 deletions
|
|
@ -6,7 +6,7 @@ metadata:
|
|||
data:
|
||||
config.yaml: |
|
||||
model:
|
||||
default: grok-4-1-fast
|
||||
default: grok-4.20-0309-reasoning
|
||||
provider: xai
|
||||
base_url: https://api.x.ai/v1
|
||||
providers:
|
||||
|
|
|
|||
|
|
@ -13,33 +13,50 @@ spec:
|
|||
labels:
|
||||
app: hermes-agent
|
||||
spec:
|
||||
automountServiceAccountToken: false
|
||||
securityContext:
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
fsGroup: 1000
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
initContainers:
|
||||
- name: fix-webui-perms
|
||||
image: busybox:1.36
|
||||
image: busybox:1.37
|
||||
imagePullPolicy: IfNotPresent
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
allowPrivilegeEscalation: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
command:
|
||||
- sh
|
||||
- -c
|
||||
args:
|
||||
- |
|
||||
chown -R 1000:1000 /data
|
||||
mkdir -p /data/.hermes/webui /data/.cache /data/.config /data/bin
|
||||
chmod -R g+rwX,o-rwx /data
|
||||
echo "✅ Hermes data permissions fixed (non-root with fsGroup)"
|
||||
volumeMounts:
|
||||
- name: hermes-data
|
||||
mountPath: /data
|
||||
containers:
|
||||
- name: hermes-agent
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
image: nousresearch/hermes-agent:latest
|
||||
|
|
@ -104,7 +121,7 @@ spec:
|
|||
value: xai
|
||||
|
||||
- name: HERMES_MODEL
|
||||
value: grok-4.1-fast
|
||||
value: grok-4.20-0309-reasoning
|
||||
|
||||
- name: OPENAI_API_KEY
|
||||
value: "dummy" # vLLM ignores this
|
||||
|
|
@ -168,11 +185,14 @@ spec:
|
|||
memory: 512Mi
|
||||
cpu: "500m"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: true
|
||||
runAsNonRoot: true
|
||||
runAsUser: 1000
|
||||
runAsGroup: 1000
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: false
|
||||
capabilities:
|
||||
drop:
|
||||
- ALL
|
||||
runAsUser: 0
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumes:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue