Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2043

Openshift Bare metal: Configure containers to set readOnlyRootFilesystem to true

XMLWordPrintable

    • Future Sustainability
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Red Hat Product Security recommends that pods be deployed with readOnlyRootFilesystem set to true in the SecurityContext, but does not require it because a successful attack can only be carried out with a combination of weaknesses and OpenShift runs with a variety of mitigating controls. 

      However, customers are increasingly asking questions about why pods from Red Hat, and deployed as part of OpenShift, do not follow common hardening recommendations. 

      Note that setting readOnlyRootFilesystem to true ensures that the container's root filesystem is mounted as read-only. This setting has nothing to do with host access. 

      For more information, see 
      https://kubernetes.io/docs/tasks/configure-pod-container/security-context/

      Setting the readOnlyRootFilesystem flag to true reduces the attack surface of your containers, preventing an attacker from manipulating the contents of your container and its root file system.

      Requirements (aka. Acceptance Criteria):

      • Impact assessment: Investigate the impact of enforcing `readOnlyRootFilesystem: true` on Bare metal.
      • Implementation (or Justification): Implement the necessary changes to enforce `readOnlyRootFilesystem: true` by default.  For any instances where `readOnlyRootFilesystem: false` is required, provide clear and concise explanations outlining the specific use cases and justifications.

              mzasepa Michal Zasepa
              linnguye.openshift Linh Nguyen
              None
              Himanshu Roy
              Dmitry Tantsur Dmitry Tantsur
              Steeve Goveas Steeve Goveas
              Avani Bhatt Avani Bhatt
              Derrick Ornelas Derrick Ornelas
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: