fix: grant API the dedicated node-control socket group
This commit is contained in:
2 files changed
+14
No files matched your search
@@ -75,8 +75,18 @@ func TestNodeControlSocketIsAPIOnly(t *testing.T) {
|
||||
}
|
||||
}
|
||||
if d.Name != SAAPI {
|
||||
if len(d.Spec.Template.Spec.SecurityContext.SupplementalGroups) != 0 {
|
||||
t.Fatal("host socket group leaked to", d.Name)
|
||||
}
|
||||
continue
|
||||
}
|
||||
groups := d.Spec.Template.Spec.SecurityContext.SupplementalGroups
|
||||
if len(groups) != 1 || groups[0] != 65532 {
|
||||
t.Fatal("API lacks host socket group", groups)
|
||||
}
|
||||
if *d.Spec.Template.Spec.SecurityContext.RunAsUser != nonRootUID || *d.Spec.Template.Spec.SecurityContext.RunAsGroup != nonRootUID {
|
||||
t.Fatal("API identity changed")
|
||||
}
|
||||
if d.Spec.Template.Spec.NodeSelector["kubernetes.io/hostname"] != "controller" {
|
||||
t.Fatal("API can run away from socket")
|
||||
}
|
||||
|
||||
@@ -489,6 +489,10 @@ func APIDeployment(p Params) *appsv1.Deployment {
|
||||
container.Env = append(container.Env, corev1.EnvVar{Name: "FELIS_NODE_CONTROL_SOCKET", Value: p.NodeControlSocket})
|
||||
}
|
||||
deployment := controlPlaneDeployment(p, SAAPI, container, volumes)
|
||||
if p.NodeControlSocket != "" {
|
||||
// The host socket uses a dedicated group; preserve the API's existing UID and volume identity.
|
||||
deployment.Spec.Template.Spec.SecurityContext.SupplementalGroups = []int64{65532}
|
||||
}
|
||||
if p.NodeControlNode != "" && p.ControllerNode == "" {
|
||||
deployment.Spec.Template.Spec.NodeSelector = map[string]string{"kubernetes.io/hostname": p.NodeControlNode}
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user