Uploaded image for project: 'AMQ Broker'
  1. AMQ Broker
  2. ENTMQBR-8895

[Docs] Restrict security context of pods by default

XMLWordPrintable

      The operator pod and the broker pods can run with a safer and restricted security context without issues. Restricting the security context of the pods by default allows to deploy a cluster of brokers also in Kubernetes namespaces with the restricted policy.

      The minimal changes to run the pods in Kubernetes namespaces with the restricted policy:

      • spec.containers[*].securityContext.allowPrivilegeEscalation: false
      • spec.initContainers[*].securityContext.allowPrivilegeEscalation: false
      • spec.ephemeralContainers[*].securityContext.allowPrivilegeEscalation: false
      • spec.securityContext.runAsNonRoot: true
      • spec.containers[*].securityContext.runAsNonRoot: true
      • spec.initContainers[*].securityContext.runAsNonRoot: true
      • spec.ephemeralContainers[*].securityContext.runAsNonRoot: true
      • spec.securityContext.seccompProfile.type: RuntimeDefault
      • spec.containers[*].securityContext.seccompProfile.type: RuntimeDefault
      • spec.initContainers[*].securityContext.seccompProfile.type: RuntimeDefault
      • spec.ephemeralContainers[*].securityContext.seccompProfile.type: RuntimeDefault
      • spec.containers[*].securityContext.capabilities.drop: ["ALL"]
      • spec.initContainers[*].securityContext.capabilities.drop: ["ALL"]
      • spec.ephemeralContainers[*].securityContext.capabilities.drop: ["ALL"]

        1. image-2024-02-26-16-33-05-391.png
          84 kB
          John Clifford
        2. image-2024-02-26-16-35-48-437.png
          56 kB
          John Clifford
        3. image-2024-02-26-16-36-23-287.png
          60 kB
          John Clifford
        4. image-2024-02-26-17-11-21-596.png
          63 kB
          John Clifford
        5. image-2024-02-26-17-18-38-907.png
          60 kB
          John Clifford
        6. image-2024-02-26-17-19-41-389.png
          66 kB
          John Clifford
        7. image-2024-03-09-23-42-00-821.png
          82 kB
          John Clifford
        8. image-2024-03-09-23-42-57-027.png
          94 kB
          John Clifford

              jcliffor@redhat.com John Clifford
              rh-messaging-ci Messaging CI
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: