Bug 1767269
| Summary: | [RFE] Seccomp profile should be enabled by default | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Tsai Li Ming <ltsai> |
| Component: | openshift-apiserver | Assignee: | Stefan Schimanski <sttts> |
| Status: | CLOSED UPSTREAM | QA Contact: | Xingxing Xia <xxia> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.1.z | CC: | aos-bugs, eparis, jialiu, jokerman, mfojtik, mharri, nstielau, pweil, sfowler, sreber, wsun, xtian, xxia |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2019-11-06 13:25:45 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Tsai Li Ming
2019-10-31 03:11:19 UTC
Kubernetes seccomp enhancement: https://github.com/kubernetes/enhancements/issues/135 Historical note: This is definitely something worth thinking about again but one item of difficulty is that this is not a backwards compatible change. While the default seccomp profile may work for *most* users it also runs the risk of breaking existing workloads unexpectedly. This is also noted in the (now closed) upstream issue https://github.com/kubernetes/kubernetes/issues/39845 The current upstream seccomp issue (https://github.com/kubernetes/kubernetes/issues/81115) proposes the following steps to help alleviate the concern: > 1. Make seccomp GA (kubernetes/enhancements#1148) > 2. Define the default profile in Kubernetes (requires profile representation in k8s) > 3. Implement a "complain mode" so issues can be detected before enabling https://github.com/kubernetes/kubernetes/issues/81115#issuecomment-520549317 upstream KEP: https://github.com/kubernetes/enhancements/pull/1257 |