XMLWordPrintable

    • Icon: Sub-task Sub-task
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • OAPE Sprint 274, OAPE Sprint 275
    • 2

      The privileged (1001) user id from the operator Dockerfile gets to run a pod from the Job, without being enforced "restricted" like SCC constraints on the upload container, which can impact security of the namespace. The lack of SecurityContextConstraints in the pod spec is one of the probable root cause.

              swghosh@redhat.com Swarup Ghosh
              swghosh@redhat.com Swarup Ghosh
              Shivprakash Muley
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: