Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-2537

Enable CAP_BPF with OCP and libcap


    • False
    • False

      1. Proposed title of this feature request

      Enable CAP_BPF with OCP and libcap

      2. What is the nature and description of the request?

      6wind fastpath needs to use EBPF for IPsec and tcpdump feature. CAP_BPF can be used provided the host OS supports it - and this means better security risk mitigation, as "SYS_ADMIN" allows too many privileges for a container.

      3. Why does the customer need this? (List the business requirements here)

      Security policy required by the workload provider.

      4. List any affected packages or components.

              rhn-support-mrussell Mark Russell
              mzasepa@redhat.com Michal Zasepa
              0 Vote for this issue
              6 Start watching this issue
