Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-31731

SELinux: kubelet running with wrong label [release-4.15]

XMLWordPrintable

    • Important
    • No
    • False
    • Fixed kubelet selinux labels on restart.
    • Bug Fix
    • In Progress

      This is a clone of issue OCPBUGS-31576. The following is the description of the original issue:

      Description of problem:

      The kubelet is running with `unconfined_service_t`. It should run as `kubelet_exec_t`. This is causing all our plugins to fail because of Selinux denial.
      
      sh-5.1# ps -AZ | grep kubelet
      system_u:system_r:unconfined_service_t:s0 8719 ? 00:24:50 kubelet
      
      This issue was previously observed and resolved in 4.14.10. 

      Version-Release number of selected component (if applicable):

      OCP 4.15

      How reproducible:

      Run ps -AZ | grep kubelet to see kubelet running with wrong label

      Steps to Reproduce:

          1.
          2.
          3.
          

      Actual results:

          Kubelet is running as unconfined_service_t

      Expected results:

          Kubelet should run as kubelet_exec_t

      Additional info:

          

              aos-node@redhat.com Node Team Bot Account
              openshift-crt-jira-prow OpenShift Prow Bot
              Min Li Min Li
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: