Loading...
Loading...
This article explains how to disable init-container in k10-grafana to run it as rootless.
Veeam Kasten for Kubernetes installation provides an instance of Grafana that is deployed automatically and can be used to query metrics from Kasten's Prometheus instance. This grafana pod is run as the user `grafana` with the UID & GID set to 472. However, by default, Veeam Kasten for Kubernetes uses an init-container, which runs as root to prepare the filesystem for grafana. Below are the default values for the Grafana in the Veeam Kasten for Kubernetes helm chart: grafana: securityContext: runAsUser: 472 runAsGroup: 472 fsGroup: 472 initChownData: enabled: true The only function of the init-container (init-chown-data) is to set up the filesystem in grafana PVC with proper permissions. With the usage of the `fsGroup` in grafana pods's securityContext or by manually changing the ownership(for shared filesystems like NFS), the usage of the init-contianer can be eliminated.
This article provides instructions for two types of storageClasses with which the grafana PVC is provisioned. Storages which supports fsGroup parameter. Shared filesystem (eg. NFS)
Click on a version to see all relevant bugs
Veeam Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.