Bug 2133654 - [pod security violation audit] Audit violation in "virt-operator" container should be fixed
Summary: [pod security violation audit] Audit violation in "virt-operator" container s...
Keywords:
Status: CLOSED DUPLICATE of bug 2128997
Alias: None
Product: Container Native Virtualization (CNV)
Classification: Red Hat
Component: Virtualization
Version: 4.11.1
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
: ---
Assignee: sgott
QA Contact: Kedar Bidarkar
URL:
Whiteboard:
Depends On:
Blocks: 2089744
TreeView+ depends on / blocked
 
Reported: 2022-10-11 05:26 UTC by SATHEESARAN
Modified: 2022-10-12 12:13 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-10-12 12:13:13 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description SATHEESARAN 2022-10-11 05:26:50 UTC
Description of problem:
-----------------------
Test run[1] that looks for 'pod security violation entries' in audit logs,against 4.11.1-20, found few audit violation.

[1] - https://main-jenkins-csb-cnvqe.apps.ocp-c1.prod.psi.redhat.com/view/cnv-tests%20runner/job/cnv-tests-runner/4297/consoleFull.

This bug is to fix violation in 'virt-operator' container.

<snip>
'pod-security.kubernetes.io/audit-violations': 'would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "virt-operator" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "virt-operator" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "virt-operator" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")'}}
</snip>

Version-Release number of selected component (if applicable):
-------------------------------------------------------------
4.11.1-20

How reproducible:
-----------------
Always

Expected results:
-----------------
No audit-violation to be found

Comment 1 Kedar Bidarkar 2022-10-12 11:55:27 UTC
Appears fixed with v4.11.1-29 HCO-Bundle

Comment 2 Kedar Bidarkar 2022-10-12 12:13:13 UTC

*** This bug has been marked as a duplicate of bug 2128997 ***


Note You need to log in before you can comment on or make changes to this bug.