Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Containers sharing sensitive host namespaces should be avoided #798

Closed
prashant6475 opened this issue Jul 19, 2023 · 4 comments
Closed

Containers sharing sensitive host namespaces should be avoided #798

prashant6475 opened this issue Jul 19, 2023 · 4 comments
Labels

Comments

@prashant6475
Copy link

We have vulnerability finding on the AKS can we have this prioritized

@ckotzbauer
Copy link
Member

ckotzbauer commented Jul 20, 2023

Kured does an "nsenter" operation, so the host-namespaces are needed. Right now this is a hard requirement for kured.

@prashant6475
Copy link
Author

let me know if u want me to help you out to test this @ckotzbauer or collab ?

@ckotzbauer
Copy link
Member

You can try to set hostPID on the Daemonset to false, Kured will come up, but will be unable to reboot your nodes.

@ckotzbauer
Copy link
Member

Duplicate of kubereboot/charts#39, I'll close this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants