Open
Description
Describe the bug
retina-agent
mounts /var/run
from host directory. This can have potential issue as it can overwrite data in the directory.
Fixes:
- Restrict access to only
/var/run/cilium
directory forretina-agent
- Investigate if we can use
DirectoryOrCreate
and removepkg/ciliumfs/setup.go
.
Platform (please complete the following information):
- OS: Linux
- Kubernetes Version: All versions
- Host: AKS
- Retina Version:
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
No status