Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Drop Linux capabilities #1610

Merged
merged 1 commit into from
Feb 2, 2022
Merged

Drop Linux capabilities #1610

merged 1 commit into from
Feb 2, 2022

Conversation

ArthurSens
Copy link
Member

Description

This is part of the initiative to tighten security in kube-prometheus

We're reducing the attack surface by dropping all Linux capabilities of all components, just keeping CAP_SYS_TIME for node-exporter because it is required by the time collector.

Following remediation docs from https://hub.armo.cloud/docs/c-0055

Type of change

What type of changes does your code introduce to the kube-prometheus? Put an x in the box that apply.

  • CHANGE (fix or feature that would cause existing functionality to not work as expected)
  • FEATURE (non-breaking change which adds functionality)
  • BUGFIX (non-breaking change which fixes an issue)
  • ENHANCEMENT (non-breaking change which improves existing functionality)
  • NONE (if none of the other choices apply. Example, tooling, build system, CI, docs, etc.)

Changelog entry

Please put a one-line changelog entry below. Later this will be copied to the changelog file.

Reduce attack surface by dropping unnecessary Linux capabilities

Signed-off-by: GitHub <noreply@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants