initial podsec

This commit is contained in:
Stavros kois
2023-02-08 18:32:49 +02:00
parent 4fa4d36d44
commit 1188aa4d54
3 changed files with 72 additions and 3 deletions
@@ -0,0 +1,68 @@
{{/* Returns Pod Security Context */}}
{{/* Call this template:
{{ include "ix.v1.common.lib.pod.securityContext" (dict "rootCtx" $ "objectData" $objectData) }}
rootCtx: The root context of the template. It is used to access the global context.
objectData: The object data to be used to render the Pod.
*/}}
{{- define "ix.v1.common.lib.pod.securityContext" -}}
{{- $rootCtx := .rootCtx -}}
{{- $objectData := .objectData -}}
{{- $secContext := dict -}}
{{/* Initialize from the "global" option */}}
{{- with $rootCtx.Values.securityContext.pod -}}
{{- $secContext = (mustDeepCopy .) -}}
{{- end -}}
{{/* Override with pod's option */}}
{{- with $objectData.podSpec.securityContext -}}
{{- $secContext = mustMergeOverwrite $secContext . -}}
{{- end -}}
{{/* TODO: Add supplemental groups
scaleGPU (44) (Only when GPU is enabled on the pod's containers)
devices (5, 10, 20, 24) (Only when devices is assigned on the pod's containers) */}}
{{/* TODO: Add sysctls
net.ipv4.ip_unprivileged_port_start: (Set to the lowest port on the pod's containers)
net.ipv4.ping_group_range: (Set to the lowest port and highest port on the pod's containers)
*/}}
{{- if not $secContext.fsGroup -}}
{{- fail "Pod - Expected non-empty <fsGroup>" -}}
{{- end -}}
{{- if not $secContext.fsGroupChangePolicy -}}
{{- fail "Pod - Expected non-empty <fsGroupChangePolicy>" -}}
{{- end -}}
{{- $policies := (list "Always" "OnRootMismatch") -}}
{{- if not (mustHas $secContext.fsGroupChangePolicy $policies) -}}
{{- fail (printf "Pod - Expected <fsGroupChangePolicy> to be one of [%s], but got [%s]" (join ", " $policies) $secContext.fsGroupChangePolicy) -}}
{{- end }}
fsGroup: {{ $secContext.fsGroup }}
fsGroupChangePolicy: {{ $secContext.fsGroupChangePolicy }}
{{- with $secContext.supplementalGroups }}
supplementalGroups:
{{- range . }}
- {{ . }}
{{- end -}}
{{- else }}
supplementalGroups: []
{{- end -}}
{{- with $secContext.sysctls }}
sysctls:
{{- range $name, $value := . }}
{{- if not $name -}}
{{- fail "Pod - Expected non-empty <name> in <sysctls>" -}}
{{- end -}}
{{- if not $value -}}
{{- fail "Pod - Expected non-empty <value> in <sysctls>" -}}
{{- end }}
- name: {{ $name }}
value: {{ $value }}
{{- end -}}
{{- else }}
sysctls: []
{{- end -}}
{{- end -}}
@@ -42,7 +42,8 @@ terminationGracePeriodSeconds: {{ . }}
tolerations:
{{- . | nindent 2 }}
{{- end }}
#TODO:securityContext:
securityContext: {{/* TODO: Unit Tests */}}
{{- include "ix.v1.common.lib.pod.securityContext" (dict "rootCtx" $rootCtx "objectData" $objectData) | trim | nindent 2 }}
#TODO:containers:
#TODO:initContainers:
{{- with (include "ix.v1.common.lib.pod.volumes" (dict "rootCtx" $rootCtx "objectData" $objectData) | trim) }}
+2 -2
View File
@@ -63,6 +63,8 @@ securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
privileged: false
seccompProfile:
type: RuntimeDefault
capabilities:
add: []
drop:
@@ -74,8 +76,6 @@ securityContext:
fsGroupChangePolicy: OnRootMismatch
supplementalGroups: []
sysctls: {}
# net.ipv4.ip_unprivileged_port_start: "0"
# net.ipv4.ping_group_range:
# -- Resources
# Can be overruled per container