-
Notifications
You must be signed in to change notification settings - Fork 108
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Harden the spo and bpf-recorder containers with custom apparmor profiles #2646
Open
ccojocar
wants to merge
4
commits into
main
Choose a base branch
from
init-apparmor
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
k8s-ci-robot
added
release-note
Denotes a PR that will be considered when it comes time to generate release notes.
kind/feature
Categorizes issue or PR as related to a new feature.
labels
Dec 23, 2024
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ccojocar The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
k8s-ci-robot
added
cncf-cla: yes
Indicates the PR's author has signed the CNCF CLA.
approved
Indicates a PR has been approved by an approver from all required OWNERS files.
labels
Dec 23, 2024
k8s-ci-robot
added
the
size/XL
Denotes a PR that changes 500-999 lines, ignoring generated files.
label
Dec 23, 2024
ccojocar
requested review from
saschagrunert
and removed request for
JAORMX and
Vincent056
December 23, 2024 16:30
cc @mhils |
ccojocar
force-pushed
the
init-apparmor
branch
from
January 17, 2025 09:26
98734a7
to
905ed1b
Compare
k8s-ci-robot
added
size/XXL
Denotes a PR that changes 1000+ lines, ignoring generated files.
and removed
size/XL
Denotes a PR that changes 500-999 lines, ignoring generated files.
labels
Jan 17, 2025
Change-Id: Iccb89ec24d4f513acff9d7828dea6a4ab3c33ef1 Signed-off-by: Cosmin Cojocar <[email protected]>
Change-Id: I8a4f7031c81fe1f47f1a0a55276b415bb6d59732 Signed-off-by: Cosmin Cojocar <[email protected]>
Change-Id: Ie5183b2d1f0550ab463f4c3d0fd713d1de6ec39b Signed-off-by: Cosmin Cojocar <[email protected]>
ccojocar
force-pushed
the
init-apparmor
branch
from
January 17, 2025 12:12
905ed1b
to
e638e83
Compare
…ofiles Change-Id: I913f1d20563311b5bb40b5f29293f1235a76a6d3 Signed-off-by: Cosmin Cojocar <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
approved
Indicates a PR has been approved by an approver from all required OWNERS files.
cncf-cla: yes
Indicates the PR's author has signed the CNCF CLA.
kind/feature
Categorizes issue or PR as related to a new feature.
release-note
Denotes a PR that will be considered when it comes time to generate release notes.
size/XXL
Denotes a PR that changes 1000+ lines, ignoring generated files.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What type of PR is this?
/kind feature
What this PR does / why we need it:
This pull request harden the security-profiles-operator and bpf-recorder containers as part of spod daemonset with custom apparmor profiles when apparmor is enabled.
These two containers run in privileged mode when the apparmor is activated.
Which issue(s) this PR fixes:
Fixes #65
Does this PR have test?
Yes
Special notes for your reviewer:
Does this PR introduce a user-facing change?