-
Bug
-
Resolution: Done
-
Critical
-
4.14.0
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
Critical
-
No
-
None
-
Approved
-
Hypershift Sprint 243
-
1
-
Done
-
Bug Fix
-
-
None
-
None
-
None
-
None
Description of problem:
[Hypershift] default KAS PSA config should be consistent with OCP enforce: privileged
Version-Release number of selected component (if applicable):
Cluster version is 4.14.0-0.nightly-2023-10-08-220853
How reproducible:
Always
Steps to Reproduce:
1. Install OCP cluster and hypershift operator 2. Create hosted cluster 3. Check the default kas config of the hosted cluster
Actual results:
The hosted cluster default kas PSA config enforce is 'restricted'
$ jq '.admission.pluginConfig.PodSecurity' < `oc extract cm/kas-config -n clusters-9cb7724d8bdd0c16a113 --confirm`
{
"location": "",
"configuration": {
"kind": "PodSecurityConfiguration",
"apiVersion": "pod-security.admission.config.k8s.io/v1beta1",
"defaults": {
"enforce": "restricted",
"enforce-version": "latest",
"audit": "restricted",
"audit-version": "latest",
"warn": "restricted",
"warn-version": "latest"
},
"exemptions": {
"usernames": [
"system:serviceaccount:openshift-infra:build-controller"
]
}
}
}
Expected results:
The hosted cluster default kas PSA config enforce should be 'privileged' in https://github.com/openshift/hypershift/blob/release-4.13/control-plane-operator/controllers/hostedcontrolplane/kas/config.go#L93
Additional info:
References: OCPBUGS-8710
- blocks
-
OCPBUGS-30644 Hosted clusters default KAS PSA config should be consistent with OCP
-
- Closed
-
- clones
-
OCPBUGS-12689 [Hypershift] hosted clusters default KAS PSA config should be consistent with OCP
-
- Closed
-
- is blocked by
-
OCPBUGS-20251 Hosted clusters default KAS PSA config should be consistent with OCP
-
- Closed
-
- is cloned by
-
OCPBUGS-30644 Hosted clusters default KAS PSA config should be consistent with OCP
-
- Closed
-
-
OCPBUGS-20251 Hosted clusters default KAS PSA config should be consistent with OCP
-
- Closed
-
- links to
-
RHSA-2023:5006
OpenShift Container Platform 4.14.z security update