From f2d7fe7bccebac8d6d6daa05f6af9429f125c401 Mon Sep 17 00:00:00 2001 From: Valentin Haudiquet Date: Thu, 10 Sep 2026 00:59:25 +0200 Subject: [PATCH] openclaw: pin image to 2026.9.3 and chown PVC mount root (operator#607) - Pin gateway image to immutable tag 2026.9.3: the stale node-cached 'latest' (old build, state schema v1) crash-looped against the PVC's DB already migrated to schema v15/16. - Add fix-data-owner init container: the operator mounts the PVC root at /home/openclaw/.openclaw with fsGroup only, leaving the mount root owned by root; OpenClaw >= 2026.9 fchmods its config dir on write and fails with EPERM (paperclipinc/openclaw-operator#607). - Ran one-time 'openclaw doctor --fix --non-interactive' against the PVC to complete the 2.0 workspace-state migration. --- .../personal/openclaw/openclaw-instance.yaml | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) diff --git a/kubernetes/personal/openclaw/openclaw-instance.yaml b/kubernetes/personal/openclaw/openclaw-instance.yaml index 79bd776..a5b6df7 100644 --- a/kubernetes/personal/openclaw/openclaw-instance.yaml +++ b/kubernetes/personal/openclaw/openclaw-instance.yaml @@ -3,6 +3,35 @@ kind: OpenClawInstance metadata: name: openclaw spec: + # Pin the gateway image to an immutable version tag. Running `latest` with + # pullPolicy=IfNotPresent let a stale node-cached image (old build, state + # schema v1) fight the PVC's DB migrated by a newer build (schema v15), + # crash-looping the container. Bump this tag alongside upstream releases. + image: + repository: ghcr.io/openclaw/openclaw + tag: "2026.9.3" + # Workaround for paperclipinc/openclaw-operator#607: the operator mounts the + # PVC root directly at /home/openclaw/.openclaw and only fsGroup is applied, + # so the mount root stays owned by root. OpenClaw >= 2026.9 fchmods its config + # dir when writing openclaw.json, which fails with EPERM for a non-owner. + # This one-shot init container chowns the mount root to the pod UID. + initContainers: + - name: fix-data-owner + image: docker.io/library/busybox:1.37 + command: ["sh", "-c", "chown 1000:1000 /data && ls -ld /data"] + securityContext: + runAsUser: 0 + runAsNonRoot: false + allowPrivilegeEscalation: false + readOnlyRootFilesystem: true + capabilities: + drop: ["ALL"] + add: ["CHOWN"] + seccompProfile: + type: RuntimeDefault + volumeMounts: + - name: data + mountPath: /data # Provider API keys come from the SOPS-encrypted Secret below. # The gateway token is auto-generated by the operator (no mDNS pairing in k8s). envFrom: