Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for SeccompDefault setting for k8s 1.25+ #3334

Merged
merged 3 commits into from
Aug 12, 2023

Conversation

cartrius-a
Copy link
Contributor

@cartrius-a cartrius-a commented Aug 9, 2023

Issue number:

Closes #2742

Description of changes:

Enable RuntimeDefault as the default seccomp profile for all workloads via kubelet-configuration. This is disabled by default.

Testing done:

I launched a 1.14.x Bottlerocket AMI and verified kubernetes.seccomp-default setting was unavailable. After updating to a custom built Bottlerocket image with my changes, the setting could be set using apiclient set settings.kubernetes.seccomp-default=true. I verified SeccompDefault was equal to true using kubectl get --raw /api/v1/nodes/<node>/proxy/configz, meaning that RuntimeDefault was being used as the default seccomp profile for the workload. I also rolled back to the older Bottlerocket image through the Admin container and verified the setting was no longer available.

Terms of contribution:

By submitting this pull request, I agree that this contribution is dual-licensed under the terms of both the Apache License, version 2.0, and the MIT license.

@jpculp jpculp requested review from stmcginnis and etungsten August 9, 2023 23:03
Copy link
Contributor

@etungsten etungsten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great job! Just a few non-blocking comments.

Enable RuntimeDefault as the default seccomp profile for all workloads
via kubelet-configuration. This is disabled by default.
@cartrius-a
Copy link
Contributor Author

Updated README.md per @etungsten's suggestion

Copy link
Contributor

@etungsten etungsten left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🥇

Diff in models:

$ diff -r aws-k8s-1.24/ aws-k8s-1.25/
Only in aws-k8s-1.25/defaults.d: 54-kubernetes-seccomp-default-false.toml
[etung] in sources/models/src [⎇  HEAD](d73a991) [$?]via 🦀 v1.71.0 
$ diff -r aws-k8s-1.25/ aws-k8s-1.26/
Only in aws-k8s-1.26/defaults.d: 54-kubernetes-aws-external-cloud-provider.toml
[etung] in sources/models/src [⎇  HEAD](d73a991) [$?]via 🦀 v1.71.0 
$ diff -r aws-k8s-1.25/ aws-k8s-1.27/
Only in aws-k8s-1.27/defaults.d: 54-kubernetes-aws-external-cloud-provider.toml
Only in aws-k8s-1.27/defaults.d: 55-kubernetes-aws-credential-provider.toml

@jpculp jpculp merged commit b2bba05 into bottlerocket-os:develop Aug 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
6 participants