Uploaded image for project: 'OpenShift API for Data Protection'
  1. OpenShift API for Data Protection
  2. OADP-6895

Investigate changes to selinux relabeling

XMLWordPrintable

    • Product / Portfolio Work
    • 3
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • ToDo
    • Very Likely
    • 0
    • None
    • Unset
    • Unknown
    • None

      Michael Fruchtman 
      @whayutin Besides the ReadWriteOncePod in 4.16. There is an upcoming improvement in SELinux labeling you should know about. Right now it is only developer preview which makes it non-viable for prod clusters. But it is coming. https://access.redhat.com/articles/7087028It will require the Velero SCC to not be privileged or use an alternative ServiceAccount with anyuid for the pods that mount the backup PVCs.  As this is Openshift only. No Velero issue will be opened to address it. (edited) 

              wnstb Wes Hayutin
              wnstb Wes Hayutin
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: