Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-1586

Reduce VolSync to align with Least Privilege principles

XMLWordPrintable

      Epic Goal

      • Work in the upstream to reduce the VolSync to align to the least privilege principles

      Why is this important?

      • Address security concerns by customer that need to implement PV replication without elevated permissions
      • OCP 4.12 will enforce pod security admission by default
      • Anticipate lower/no adoption of VolSync unless we address these security concerns

      Scenarios

      1. Option for customer to allow elevated privileges if it is not a security concern.
      2. Work in the upstream community to naturally allow VolSync to run regardless. 

      Acceptance Criteria

      • CI - MUST be running successfully with tests automated
      • Release Technical Enablement - Provide necessary release enablement details and documents.
      • ...

      Dependencies (internal and external)

      1. RSync, RClone and Restic movers PR in Upstream

      Previous Work (Optional):

      1. N/A

      Open questions::

      1. N/A

      Done Checklist

      • CI - CI is running, tests are automated and merged.
      • Release Enablement <link to Feature Enablement Presentation>
      • DEV - Upstream code and tests merged: <link to meaningful PR or GitHub Issue>
      • DEV - Upstream documentation merged: <link to meaningful PR or GitHub Issue>
      • DEV - Downstream build attached to advisory: <link to errata>
      • QE - Test plans in Polarion: <link or reference to Polarion>
      • QE - Automated tests merged: <link or reference to automated tests>
      • DOC - Downstream documentation merged: <link to meaningful PR>

            jbrent@redhat.com Jeffrey Brent (Inactive)
            jbrent@redhat.com Jeffrey Brent (Inactive)
            Tesshu Flower Tesshu Flower
            Jeffrey Brent Jeffrey Brent (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: