diff --git a/kubernetes/personal/openclaw/openclaw-instance.yaml b/kubernetes/personal/openclaw/openclaw-instance.yaml index 79bd776..a5b6df7 100644 --- a/kubernetes/personal/openclaw/openclaw-instance.yaml +++ b/kubernetes/personal/openclaw/openclaw-instance.yaml @@ -3,6 +3,35 @@ kind: OpenClawInstance metadata: name: openclaw spec: + # Pin the gateway image to an immutable version tag. Running `latest` with + # pullPolicy=IfNotPresent let a stale node-cached image (old build, state + # schema v1) fight the PVC's DB migrated by a newer build (schema v15), + # crash-looping the container. Bump this tag alongside upstream releases. + image: + repository: ghcr.io/openclaw/openclaw + tag: "2026.9.3" + # Workaround for paperclipinc/openclaw-operator#607: the operator mounts the + # PVC root directly at /home/openclaw/.openclaw and only fsGroup is applied, + # so the mount root stays owned by root. OpenClaw >= 2026.9 fchmods its config + # dir when writing openclaw.json, which fails with EPERM for a non-owner. + # This one-shot init container chowns the mount root to the pod UID. + initContainers: + - name: fix-data-owner + image: docker.io/library/busybox:1.37 + command: ["sh", "-c", "chown 1000:1000 /data && ls -ld /data"] + securityContext: + runAsUser: 0 + runAsNonRoot: false + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + add: ["CHOWN"] + seccompProfile: + type: RuntimeDefault + volumeMounts: + - name: data + mountPath: /data # Provider API keys come from the SOPS-encrypted Secret below. # The gateway token is auto-generated by the operator (no mDNS pairing in k8s). envFrom: