serving icon indicating copy to clipboard operation
serving copied to clipboard

Support user namespaces in Serving

Open psschwei opened this issue 3 years ago • 1 comments

Describe the feature

Kubernetes v1.25 will add support for user namespaces as an alpha feature. This will improve security through increased pod to node/pod isolation and should also help with the multi-tenancy work stream.

For now, I'm proposing doing some initial exploratory work around what it would take to use user namespaces for Knative pods.

/area API /area security

/assign

psschwei avatar Aug 11 '22 14:08 psschwei

@psschwei: The label(s) area/security cannot be applied, because the repository doesn't have them.

In response to this:

Describe the feature

Kubernetes v1.25 will add support for user namespaces as an alpha feature. This will improve security through increased pod to node/pod isolation and should also help with the multi-tenancy work stream.

For now, I'm proposing doing some initial exploratory work around what it would take to use user namespaces for Knative pods.

/area API /area security

/assign

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

knative-prow[bot] avatar Aug 11 '22 14:08 knative-prow[bot]

This issue is stale because it has been open for 90 days with no activity. It will automatically close after 30 more days of inactivity. Reopen the issue with /reopen. Mark the issue as fresh by adding the comment /remove-lifecycle stale.

github-actions[bot] avatar Jan 12 '23 01:01 github-actions[bot]

/lifecycle frozen

psschwei avatar Jan 12 '23 13:01 psschwei