Bug 1843219

Summary: node-labeller SCC is privileged, which appears too relaxed
Product: Container Native Virtualization (CNV) Reporter: Kedar Bidarkar <kbidarka>
Component: SSPAssignee: Karel Šimon <ksimon>
Status: CLOSED ERRATA QA Contact: Kedar Bidarkar <kbidarka>
Severity: high Docs Contact:
Priority: high    
Version: 2.4.0CC: cnv-qe-bugs, fdeutsch, ncredi
Target Milestone: ---   
Target Release: 2.4.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: kubevirt-ssp-operator-container-v2.4.0-58 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-07-28 19:10:09 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1847594    
Bug Blocks:    

Description Kedar Bidarkar 2020-06-02 19:34:27 UTC
Description of problem:

node-labeller SCC is privileged, which appears too relaxed.

All the pods in the hco_namespace/openshift-cnv namespace should either be "restricted" or belong to a custom SCC.

node-labeller with privileged SCC appears too relaxed, probably we want a custom SCC here ?


Version-Release number of selected component (if applicable):
CNV-2.4


How reproducible:
[kbidarka@kbidarka-host auth]$ oc get pod kubevirt-node-labeller-b5bqt -o yaml -n openshift-cnv | grep scc 
    openshift.io/scc:  "privileged"

Steps to Reproduce:
1. check for kubevirt-node-labeller-b5bqt pod SCC
2. oc get pod kubevirt-node-labeller-b5bqt -o yaml -n openshift-cnv | grep scc
3.

Actual results:

    openshift.io/scc:  "privileged"
Current SCC "privileged" seems too relaxed.


Expected results:
The idea is to avoid having pods running in hco_namespace/openshit-cnv with "privileged" SCC.

Should have an SCC, which is not too relaxed

Additional info:

Earlier as this pod functionality was being merged with virt-handler, thought this bug wouldn't  be necessary, but as kubevirt-node-labeller-b5bqt   is back, decided to have this bug to track this issue.

Comment 1 Kedar Bidarkar 2020-07-13 11:55:24 UTC
Currently cannot verify this bug, due to the below issue, 
https://bugzilla.redhat.com/show_bug.cgi?id=1847594#c3

Added the bug to Depends on

Comment 4 Kedar Bidarkar 2020-07-17 16:48:47 UTC
This is bug is now fixed,

kubevirt-node-labeller-fvmlm
    openshift.io/scc: kubevirt-node-labeller
kubevirt-node-labeller-gxpxn
    openshift.io/scc: kubevirt-node-labeller
kubevirt-node-labeller-jflzg
    openshift.io/scc: kubevirt-node-labeller

Comment 7 errata-xmlrpc 2020-07-28 19:10:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2020:3194