Bug 1917442
| Summary: | Unable to set protectKernelDefaults | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Juan Antonio Osorio <josorior> |
| Component: | Node Tuning Operator | Assignee: | Jiří Mencák <jmencak> |
| Status: | CLOSED NOTABUG | QA Contact: | Mike Fiedler <mifiedle> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 4.7 | CC: | sejug |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2021-01-18 15:13:19 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Juan Antonio Osorio
2021-01-18 13:50:25 UTC
Thank you for your report, however, this is not NTO's bug. NTO is responsible for wrapping around and enabling the Tuned daemon to run in the OpenShift environment and achieve as much compatibility with its functionality as possible. Your report is a feature request and those are handled by Jira cards. However, based on Ryan's comment in https://bugzilla.redhat.com/show_bug.cgi?id=1898933#c3 , #c6 and looking into this a bit more, we believe there is not much to gain in terms of security by implementing this as you'll still have to use CAP_SYS_ADMIN by the kubelet and a lot to lose in terms of complexity and potential issues already pointed out in 1898933. |