mirror of
https://github.com/vhaudiquet/homeprod.git
synced 2026-09-11 11:41:14 +00:00
openclaw: pin image to 2026.9.3 and chown PVC mount root (operator#607)
- Pin gateway image to immutable tag 2026.9.3: the stale node-cached 'latest' (old build, state schema v1) crash-looped against the PVC's DB already migrated to schema v15/16. - Add fix-data-owner init container: the operator mounts the PVC root at /home/openclaw/.openclaw with fsGroup only, leaving the mount root owned by root; OpenClaw >= 2026.9 fchmods its config dir on write and fails with EPERM (paperclipinc/openclaw-operator#607). - Ran one-time 'openclaw doctor --fix --non-interactive' against the PVC to complete the 2.0 workspace-state migration.
This commit is contained in:
@@ -3,6 +3,35 @@ kind: OpenClawInstance
|
||||
metadata:
|
||||
name: openclaw
|
||||
spec:
|
||||
# Pin the gateway image to an immutable version tag. Running `latest` with
|
||||
# pullPolicy=IfNotPresent let a stale node-cached image (old build, state
|
||||
# schema v1) fight the PVC's DB migrated by a newer build (schema v15),
|
||||
# crash-looping the container. Bump this tag alongside upstream releases.
|
||||
image:
|
||||
repository: ghcr.io/openclaw/openclaw
|
||||
tag: "2026.9.3"
|
||||
# Workaround for paperclipinc/openclaw-operator#607: the operator mounts the
|
||||
# PVC root directly at /home/openclaw/.openclaw and only fsGroup is applied,
|
||||
# so the mount root stays owned by root. OpenClaw >= 2026.9 fchmods its config
|
||||
# dir when writing openclaw.json, which fails with EPERM for a non-owner.
|
||||
# This one-shot init container chowns the mount root to the pod UID.
|
||||
initContainers:
|
||||
- name: fix-data-owner
|
||||
image: docker.io/library/busybox:1.37
|
||||
command: ["sh", "-c", "chown 1000:1000 /data && ls -ld /data"]
|
||||
securityContext:
|
||||
runAsUser: 0
|
||||
runAsNonRoot: false
|
||||
allowPrivilegeEscalation: false
|
||||
readOnlyRootFilesystem: true
|
||||
capabilities:
|
||||
drop: ["ALL"]
|
||||
add: ["CHOWN"]
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
volumeMounts:
|
||||
- name: data
|
||||
mountPath: /data
|
||||
# Provider API keys come from the SOPS-encrypted Secret below.
|
||||
# The gateway token is auto-generated by the operator (no mDNS pairing in k8s).
|
||||
envFrom:
|
||||
|
||||
Reference in New Issue
Block a user