Bug 1806915
Summary: | openshift-service-ca: Some core components are in openshift.io/run-level 1 and are bypassing SCC, but should not be | ||
---|---|---|---|
Product: | OpenShift Container Platform | Reporter: | Stefan Schimanski <sttts> |
Component: | apiserver-auth | Assignee: | Standa Laznicka <slaznick> |
Status: | CLOSED ERRATA | QA Contact: | scheng |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4.4 | CC: | aos-bugs, ccoleman, eparis, jialiu, jokerman, mfojtik, nhale, nstielau, sfowler, wsun, xiyuan, xtian, xxia |
Target Milestone: | --- | Keywords: | Reopened |
Target Release: | 4.7.0 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
Cause:
The namespace openshift-service-ca was labelled with "openshift.io/run-level: 1".
Consequence:
The pods inside this namespace would run with extra privileges.
Fix:
Since the label is no longer necessary to avoid components' circular dependency, it was removed.
Result:
The service-ca pods had their privileges scoped down.
|
Story Points: | --- |
Clone Of: | 1805488 | Environment: | |
Last Closed: | 2021-02-24 15:10:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1805488, 1966621 |
Comment 1
Standa Laznicka
2020-03-06 09:01:42 UTC
Reopened and moved to 4.5. Reopened and moved to 4.5. No progress in 4.5 about this (mirroring changes to the operator bug: https://bugzilla.redhat.com/show_bug.cgi?id=1806917#c3) Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Moderate: OpenShift Container Platform 4.7.0 security, bug fix, and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2020:5633 |