Uploaded image for project: 'OpenShift Authentication'
  1. OpenShift Authentication
  2. AUTH-222

Pod Security compliance: openshift-kube-descheduler-operator and its operand

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • None
    • Auth - Sprint 219

      openshift-kube-descheduler-operator must comply to pod security. The current audit warning is:

      namespace is:  openshift-kube-descheduler-operator
      pod name is:  descheduler-5c89d4544c-wqkpq
      container: openshift-descheduler
      pod name is:  descheduler-operator-666b469f87-x85t5
      container: descheduler-operator
      W0511 16:07:09.971492       1 warnings.go:70] would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "openshift-descheduler" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "openshift-descheduler" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "openshift-descheduler" must set securityContext.runAsNonRoot=true), seccompProfile (pod or container "openshift-descheduler" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
      W0511 16:07:16.265610       1 warnings.go:70] would violate PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "openshift-descheduler" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "openshift-descheduler" must set securityContext.capabilities.drop=["ALL"]), runAsNonRoot != true (pod or container "openshift-descheduler" must set securityContext.runAsNonRoot=true), seccompProfile (pod or container "openshift-descheduler" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")
      namespace is:  openshift-kube-scheduler

              jchaloup@redhat.com Jan Chaloupka
              knarra@redhat.com Rama Kasturi Narra
              None
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: