<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>52127</bug_id>
          
          <creation_ts>2024-11-20 21:12:45 +0300</creation_ts>
          <short_desc>Локальный регистратор: нет доступа к локальному контейнеру Nginx</short_desc>
          <delta_ts>2024-11-20 21:12:45 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Branch p10</product>
          <component>podsec</component>
          <version>не указана</version>
          <rep_platform>x86_64</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>NEW</bug_status>
          <resolution></resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P5</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Evgeny Shesteperov">alimektor</reporter>
          <assigned_to name="kaf@altlinux.org">kaf</assigned_to>
          
          
          <qa_contact name="qa-p10@altlinux.org">qa-p10</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>254841</commentid>
    <comment_count>0</comment_count>
    <who name="Evgeny Shesteperov">alimektor</who>
    <bug_when>2024-11-20 21:12:45 +0300</bug_when>
    <thetext>Версия

-   podsec-1.0.10-alt7

Шаги воспроизведения

Настройка проводилась согласно сценарию с локальным регистром по Вики:
https://www.altlinux.org/Rootless_kubernetes

    [imagemaker]$ podman pull --tls-verify docker.io/library/nginx:1.14.2

    [imagemaker]$ podman tag docker.io/library/nginx:1.14.2 registry.local/nginx

    [imagemaker]$ podman push --tls-verify=false --sign-by=imagemaker@test.ru registry.local/nginx
    # cat &gt; deploy.yaml &lt;&lt; &apos;EOF&apos;
    apiVersion: apps/v1
    kind: Deployment
    metadata:
      name: nginx-deployment
    spec:
      selector:
        matchLabels:
          app: nginx
      replicas: 2
      template:
        metadata:
          labels:
            app: nginx
        spec:
          containers:
          - name: nginx
            image: registry.local/nginx
            ports:
            - containerPort: 80
    ---
    apiVersion: v1
    kind: Service
    metadata:
      name: nginx
      labels:
        app: nginx
    spec:
      type: NodePort
      ports:
      - port: 80
        targetPort: 80
      selector:
        app: nginx
    EOF

    [master]# export PATH=&quot;/usr/libexec/podsec/u7s/bin/:${PATH}&quot; &amp;&amp; kubectl apply -f deploy.yaml

    [master]# kubectl get service nginx -o jsonpath=&apos;{.spec.ports[0].nodePort}&apos;

    [worker]# echo -e &quot;admin\nadmin&quot; | passwd u7s-admin

    [worker]# ssh -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -o IdentitiesOnly=yes u7s-admin@localhost

    [u7s-admin]$ curl $(hostname -i):&lt;&lt;nginx_port&gt;&gt;

Ожидаемый результат: Получен доступ к контейнеру.

Фактический результат: Тест с помощью curl не проходит.

В P11 не воспроизводится.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>