aws-efs-csi-driver icon indicating copy to clipboard operation
aws-efs-csi-driver copied to clipboard

Enable SecurityContext on container level

Open Shwethamuralikrishnaa opened this issue 2 years ago • 2 comments

Is your feature request related to a problem? Please describe. We are not able to define containerSecurityContext, this causes efs-csi-driver containers to get flagged by security scanner.

Describe the solution you'd like in detail The chart must support the containerSecurityContext.

Describe alternatives you've considered

Additional context

Shwethamuralikrishnaa avatar Aug 04 '22 07:08 Shwethamuralikrishnaa

@wongma7 @Ashley-wenyizha @RomanBednar can you please take a look?

pierluigilenoci avatar Aug 08 '22 10:08 pierluigilenoci

@wongma7 @Ashley-wenyizha @RomanBednar can you please take a look?

pierluigilenoci avatar Aug 26 '22 12:08 pierluigilenoci

The Kubernetes project currently lacks enough contributors to adequately respond to all issues and PRs.

This bot triages issues and PRs according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue or PR as fresh with /remove-lifecycle stale
  • Mark this issue or PR as rotten with /lifecycle rotten
  • Close this issue or PR with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Nov 24 '22 13:11 k8s-triage-robot

/remove-lifecycle stale

pierluigilenoci avatar Nov 28 '22 11:11 pierluigilenoci

@mskanth972 @mjsoyeon could you please take a look? @Ashley-wenyizha @dschunack @lmouhib who should I ask for feedback?

pierluigilenoci avatar Nov 28 '22 11:11 pierluigilenoci

/assign @jsafrane

dschunack avatar Dec 20 '22 10:12 dschunack

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

  • After 90d of inactivity, lifecycle/stale is applied
  • After 30d of inactivity since lifecycle/stale was applied, lifecycle/rotten is applied
  • After 30d of inactivity since lifecycle/rotten was applied, the issue is closed

You can:

  • Mark this issue as fresh with /remove-lifecycle stale
  • Close this issue with /close
  • Offer to help out with Issue Triage

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

k8s-triage-robot avatar Mar 20 '23 11:03 k8s-triage-robot

/remove-lifecycle stale

pierluigilenoci avatar Mar 20 '23 12:03 pierluigilenoci

@jsafrane, any news on this?

pierluigilenoci avatar Mar 20 '23 12:03 pierluigilenoci

Hi @pierluigilenoci, thanks for bringing here, we will plan to work on this soon and add the respected fields readOnlyRootFilesystem , allowPrivilegeEscalation under the security context.

mskanth972 avatar Apr 28 '23 05:04 mskanth972

/unassign Please don't assign me to random issues without my consent.

jsafrane avatar May 03 '23 11:05 jsafrane

/kind enhancement

RyanStan avatar May 15 '23 14:05 RyanStan

@RyanStan: The label(s) kind/enchancement cannot be applied, because the repository doesn't have them.

In response to this:

/kind enchancement

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

k8s-ci-robot avatar May 15 '23 14:05 k8s-ci-robot

/kind feature

RyanStan avatar May 15 '23 14:05 RyanStan

Closing the issue as PR for enabling security context for container level is merged and will mark it in the coming release.

mskanth972 avatar May 17 '23 18:05 mskanth972

/close

mskanth972 avatar May 17 '23 18:05 mskanth972

@mskanth972: Closing this issue.

In response to this:

/close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

k8s-ci-robot avatar May 17 '23 18:05 k8s-ci-robot