Bug 1843219 - node-labeller SCC is privileged, which appears too relaxed
Summary: node-labeller SCC is privileged, which appears too relaxed
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Container Native Virtualization (CNV)
Classification: Red Hat
Component: SSP
Version: 2.4.0
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 2.4.0
Assignee: Karel Šimon
QA Contact: Kedar Bidarkar
URL:
Whiteboard:
Depends On: 1847594
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-06-02 19:34 UTC by Kedar Bidarkar
Modified: 2020-07-28 19:10 UTC (History)
3 users (show)

Fixed In Version: kubevirt-ssp-operator-container-v2.4.0-58
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-07-28 19:10:09 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github MarSik kubevirt-ssp-operator pull 191 0 None closed add node-labeller scc 2020-11-10 07:25:11 UTC
Red Hat Product Errata RHSA-2020:3194 0 None None None 2020-07-28 19:10:26 UTC

Description Kedar Bidarkar 2020-06-02 19:34:27 UTC
Description of problem:

node-labeller SCC is privileged, which appears too relaxed.

All the pods in the hco_namespace/openshift-cnv namespace should either be "restricted" or belong to a custom SCC.

node-labeller with privileged SCC appears too relaxed, probably we want a custom SCC here ?


Version-Release number of selected component (if applicable):
CNV-2.4


How reproducible:
[kbidarka@kbidarka-host auth]$ oc get pod kubevirt-node-labeller-b5bqt -o yaml -n openshift-cnv | grep scc 
    openshift.io/scc:  "privileged"

Steps to Reproduce:
1. check for kubevirt-node-labeller-b5bqt pod SCC
2. oc get pod kubevirt-node-labeller-b5bqt -o yaml -n openshift-cnv | grep scc
3.

Actual results:

    openshift.io/scc:  "privileged"
Current SCC "privileged" seems too relaxed.


Expected results:
The idea is to avoid having pods running in hco_namespace/openshit-cnv with "privileged" SCC.

Should have an SCC, which is not too relaxed

Additional info:

Earlier as this pod functionality was being merged with virt-handler, thought this bug wouldn't  be necessary, but as kubevirt-node-labeller-b5bqt   is back, decided to have this bug to track this issue.

Comment 1 Kedar Bidarkar 2020-07-13 11:55:24 UTC
Currently cannot verify this bug, due to the below issue, 
https://bugzilla.redhat.com/show_bug.cgi?id=1847594#c3

Added the bug to Depends on

Comment 4 Kedar Bidarkar 2020-07-17 16:48:47 UTC
This is bug is now fixed,

kubevirt-node-labeller-fvmlm
    openshift.io/scc: kubevirt-node-labeller
kubevirt-node-labeller-gxpxn
    openshift.io/scc: kubevirt-node-labeller
kubevirt-node-labeller-jflzg
    openshift.io/scc: kubevirt-node-labeller

Comment 7 errata-xmlrpc 2020-07-28 19:10:09 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2020:3194


Note You need to log in before you can comment on or make changes to this bug.