Uploaded image for project: 'OpenShift Node'
  1. OpenShift Node
  2. OCPNODE-869

Create drop-in crio.conf to make default seccomp option change an opt-in

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • openshift-4.11
    • None
    • None
    • OCPNODE Sprint 217

      crio will change the default value of seccomp_use_default_when_empty from false to true in crio 1.24 and later versions.
      so set seccomp_use_default_when_empty  = true in the template.
      In order to not break current clusters, for those upgrade users, create a machine-config to have drop-in crio.conf file with seccomp_use_default_when_empty = false. So seccomp_use_default_when_empty change can be an opt-in for upgraded users, users will have the option to delete the MC associated with this file when they are ready to
      consume the seccomp_use_default_when_empty = true for their workload

            qiwan233 Qi Wang
            qiwan233 Qi Wang
            Sunil Choudhary Sunil Choudhary
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: