Uploaded image for project: 'Maistra'
  1. Maistra
  2. MAISTRA-2525

CNI pods don't need hostNetwork

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Minor Minor
    • maistra-2.1.0
    • None
    • CNI
    • None
    • Sprint 7

      install-cni pods which run in the same namespace as the operator (typically openshift-operators) currently have the `hostNetwork` permission, but it isn't really necessary.

       

      Given the pods run with elevated privileges, having access to the host network is dangerous.

       

      We should be able to remove this permission and have no side effect, everything must continue to work just fine with regards to CNI and sidecar injection.

            jsantana@redhat.com Jonh Wendell
            jsantana@redhat.com Jonh Wendell
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: