Skip to content

Conversation

FxKu
Copy link
Member

@FxKu FxKu commented Jan 22, 2021

in the process of switching all pods to non-privileged pods the use privilege for a privileged PodSecurityPolicy is obsolete. However, Pods holding this privilege before might still escalate to such a PSP and will then face issues when the psp privilege is missing in the RBAC. Setting AllowPrivilegeEscalation: false on the container's securityContext should prevent this. The value will be based on what's configured for spilo_privileged.

@Jan-M
Copy link
Member

Jan-M commented Jan 22, 2021

👍

1 similar comment
@FxKu
Copy link
Member Author

FxKu commented Jan 22, 2021

👍

@FxKu FxKu merged commit 4ea0b5f into master Jan 22, 2021
@FxKu FxKu added this to the 1.7 milestone Jan 27, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants