Uploaded image for project: 'OpenShift Virtualization'
  1. OpenShift Virtualization
  2. CNV-68501

CNV tracker for namespace support vsock

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Major Major
    • CNV v4.21.0
    • None
    • CNV Infrastructure
    • None
    • cnv-tracker-namespace-support-vsock
    • Product / Portfolio Work
    • 77
      • we know in which RHEL version we can allow securely VSOCK in CNV
    • To Do
    • CNV-40413Run commands in a VM guest operating system
    • 100% To Do, 0% In Progress, 0% Done
    • dev-ready, po-ready, qe-ready, ux-ready
    • No

      Goal

      To enable VSOCK in CNV CNV-64172 in a secure way,  the access the the VSOCK has to be limited to the namespce of a single virt-laucher pod.

      This discussed upstream in https://lore.kernel.org/netdev/20250827-vsock-vmtest-v5-0-0ba580bede5b@meta.com/ , and tracked downstream in https://issues.redhat.com/browse/RHELPLAN-20414 .

      User Stories

      • As a VM owner, I want to be sure that no other pod on the same host is able to access the VSOCK of my VM.

      Non-Requirements

      • List of things not included in this epic, to alleviate any doubt raised during the grooming process.

      Notes

      • Any additional details or decisions made/needed

              victortoso@redhat.com Victor Toso
              unassigned_jira Unassigned
              Geetika Kapoor Geetika Kapoor
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: