To solve this issue we need to create emptyDir volumes for these two folders.
If you are using Helm to deploy Kong, the current Kong Helm chart already mounts dedicated emptyDir volumes at /tmp (tmpDir.sizeLimit, default 1Gi) and /kong_prefix/ (prefixDir.sizeLimit, default 256Mi) on both the init container and the main proxy container by default — confirmed live via helm template on a current chart release. You can find the current chart’s values reference in the chart’s values.yaml (tmpDir/prefixDir keys); see related resources for the link.
If you use YAML files for deployment, you can create volumes and volumeMounts with securityContext similar to the example below. (You can also use Helm with the --dry-run flag to generate the YAML files for you.)
spec:
securityContext:
allowPrivilegeEscalation: false
privileged: false
readOnlyRootFilesystem: true
volumeMounts:
- name: kong-prefix-dir
mountPath: /kong_prefix/
- name: kong-tmp
mountPath: /tmp
volumes:
- name: kong-prefix-dir
emptyDir: {}
- name: kong-tmp
emptyDir: {}
Now you should be able to start Kong with readOnlyRootFilesystem: true.