-
Epic
-
Resolution: Done-Errata
-
Major
-
None
-
None
-
Run Manila pod components at minimum privilege escalation level
-
False
-
-
False
-
Not Selected
-
Committed
-
No Docs Impact
-
To Do
-
manila-operator-container-1.0.4-4
-
manila-operator-container-1.0.4-4
-
Proposed
-
Proposed
-
0% To Do, 0% In Progress, 100% Done
-
-
Currently Manila services are executed using root user. This brings security concerns other than violating most of the security context requirements.
When possible, move Pods to run services (Manila API, Scheduler, Share and related jobs) as Manila user/group.
- links to
-
RHSA-2024:140345 RHOSO OpenStack Podified operator containers security update