Uploaded image for project: 'AMQ Streams'
  1. AMQ Streams
  2. ENTMQST-4826

Set restricted security context as default in the Strimzi Helm chart

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • None
    • False
    • None
    • False

      Currently, the Helm Chart sets by default no security context, and users who want to set it to something specific can do so through the values options. Ideally, we would want to set the context to match the restricted profile by default since Strimzi Cluster Operator runs fine with it and it would follow the principle of giving it the least possible privilege.

      However, this change is not backwards compatible. this is because while the operator itself can run under these security context rules, it might conflict for many users with their existing rules which might for example enforce some particular user IDs etc. So it would break the Helm chart for them. They would be able to work around it by setting the right values when installing the Helm Chart. But they would need to be aware of it.

      So in the community call on 20.4.2023, we decided to postpone it for a release with other major changes. E.g. the 1.0.0 which would likely also bring the CRD changes and many other things which would require the user's attention. This decision was taken as part of the discussion about #8417 which it replaces.

            Unassigned Unassigned
            scholzj JAkub Scholz
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated: