fix: grant API the dedicated node-control socket group
This commit is contained in:
2 files changed
+14
No files matched your search
@@ -75,8 +75,18 @@ func TestNodeControlSocketIsAPIOnly(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
if d.Name != SAAPI {
|
if d.Name != SAAPI {
|
||||||
|
if len(d.Spec.Template.Spec.SecurityContext.SupplementalGroups) != 0 {
|
||||||
|
t.Fatal("host socket group leaked to", d.Name)
|
||||||
|
}
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
groups := d.Spec.Template.Spec.SecurityContext.SupplementalGroups
|
||||||
|
if len(groups) != 1 || groups[0] != 65532 {
|
||||||
|
t.Fatal("API lacks host socket group", groups)
|
||||||
|
}
|
||||||
|
if *d.Spec.Template.Spec.SecurityContext.RunAsUser != nonRootUID || *d.Spec.Template.Spec.SecurityContext.RunAsGroup != nonRootUID {
|
||||||
|
t.Fatal("API identity changed")
|
||||||
|
}
|
||||||
if d.Spec.Template.Spec.NodeSelector["kubernetes.io/hostname"] != "controller" {
|
if d.Spec.Template.Spec.NodeSelector["kubernetes.io/hostname"] != "controller" {
|
||||||
t.Fatal("API can run away from socket")
|
t.Fatal("API can run away from socket")
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -489,6 +489,10 @@ func APIDeployment(p Params) *appsv1.Deployment {
|
|||||||
container.Env = append(container.Env, corev1.EnvVar{Name: "FELIS_NODE_CONTROL_SOCKET", Value: p.NodeControlSocket})
|
container.Env = append(container.Env, corev1.EnvVar{Name: "FELIS_NODE_CONTROL_SOCKET", Value: p.NodeControlSocket})
|
||||||
}
|
}
|
||||||
deployment := controlPlaneDeployment(p, SAAPI, container, volumes)
|
deployment := controlPlaneDeployment(p, SAAPI, container, volumes)
|
||||||
|
if p.NodeControlSocket != "" {
|
||||||
|
// The host socket uses a dedicated group; preserve the API's existing UID and volume identity.
|
||||||
|
deployment.Spec.Template.Spec.SecurityContext.SupplementalGroups = []int64{65532}
|
||||||
|
}
|
||||||
if p.NodeControlNode != "" && p.ControllerNode == "" {
|
if p.NodeControlNode != "" && p.ControllerNode == "" {
|
||||||
deployment.Spec.Template.Spec.NodeSelector = map[string]string{"kubernetes.io/hostname": p.NodeControlNode}
|
deployment.Spec.Template.Spec.NodeSelector = map[string]string{"kubernetes.io/hostname": p.NodeControlNode}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in new issue
Block a user