core: define empty securityContext for pods to fix CIS 5.7.3

Resolves CIS benchmark rule 5.7.3, Pods part. SecurityContext
should be explicitly defined in pod level of Pod spec section.
It is sufficient to specify empty securityContext to satisfy
CIS 5.7.3 rule.

5.7.3 Apply Security Context to Your Pods and Containers

When designing your containers and pods, make sure
that you configure the security context for your pods,
containers, and volumes.

Signed-off-by: Peter Razumovsky <prazumovsky@mirantis.com>
This commit is contained in:
Peter Razumovsky
2024-10-09 16:10:03 +04:00
parent 0465908912
commit 516eab4d8a
27 changed files with 29 additions and 2 deletions
+1
View File
@@ -162,6 +162,7 @@ func (c *ClusterController) cleanUpJobTemplateSpec(cluster *cephv1.CephCluster,
Volumes: volumes,
RestartPolicy: v1.RestartPolicyOnFailure,
PriorityClassName: cephv1.GetCleanupPriorityClassName(cluster.Spec.PriorityClassNames),
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
HostNetwork: opcontroller.EnforceHostNetwork(),
},
+1
View File
@@ -61,6 +61,7 @@ func (c *Cluster) makeDeployment(mgrConfig *mgrConfig) (*apps.Deployment, error)
Containers: []v1.Container{
c.makeMgrDaemonContainer(mgrConfig),
},
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: serviceAccountName,
RestartPolicy: v1.RestartPolicyAlways,
Volumes: volumes,
+1
View File
@@ -190,6 +190,7 @@ func (c *Cluster) makeMonPod(monConfig *monConfig, canary bool) (*corev1.Pod, er
Volumes: controller.DaemonVolumesBase(monConfig.DataPathMap, keyringStoreName, c.spec.DataDirHostPath),
HostNetwork: monConfig.UseHostNetwork,
PriorityClassName: cephv1.GetMonPriorityClassName(c.spec.PriorityClassNames),
SecurityContext: &corev1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
}
@@ -121,6 +121,7 @@ func (r *ReconcileNode) createOrUpdateCephCrash(node corev1.Node, tolerations []
HostNetwork: cephCluster.Spec.Network.IsHost(),
Volumes: volumes,
PriorityClassName: cephv1.GetCrashCollectorPriorityClassName(cephCluster.Spec.PriorityClassNames),
SecurityContext: &corev1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
@@ -144,6 +144,7 @@ func (r *ReconcileNode) createOrUpdateCephExporter(node corev1.Node, tolerations
Volumes: volumes,
PriorityClassName: cephv1.GetCephExporterPriorityClassName(cephCluster.Spec.PriorityClassNames),
TerminationGracePeriodSeconds: &terminationGracePeriodSeconds,
SecurityContext: &corev1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
@@ -110,6 +110,7 @@ func (r *ReconcileNode) createOrUpdateCephCron(cephCluster cephv1.CephCluster, c
RestartPolicy: corev1.RestartPolicyNever,
HostNetwork: cephCluster.Spec.Network.IsHost(),
Volumes: volumes,
SecurityContext: &corev1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
@@ -161,6 +161,7 @@ func (c *Cluster) getKeyRotationPodTemplateSpec(osdProps osdProperties, osd OSDI
HostNetwork: c.spec.Network.IsHost(),
PriorityClassName: cephv1.GetOSDPriorityClassName(c.spec.PriorityClassNames),
SchedulerName: osdProps.schedulerName,
SecurityContext: &v1.PodSecurityContext{},
},
}
if c.spec.Network.IsHost() {
@@ -158,6 +158,7 @@ func (c *Cluster) provisionPodTemplateSpec(osdProps osdProperties, restart v1.Re
HostNetwork: opcontroller.EnforceHostNetwork(),
PriorityClassName: cephv1.GetOSDPriorityClassName(c.spec.PriorityClassNames),
SchedulerName: osdProps.schedulerName,
SecurityContext: &v1.PodSecurityContext{},
}
if c.spec.Network.IsHost() {
podSpec.DNSPolicy = v1.DNSClusterFirstWithHostNet
+3 -2
View File
@@ -631,8 +631,9 @@ func (c *Cluster) makeDeployment(osdProps osdProperties, osd *OSDInfo, provision
WorkingDir: opconfig.VarLogCephDir,
},
},
Volumes: volumes,
SchedulerName: osdProps.schedulerName,
Volumes: volumes,
SecurityContext: &v1.PodSecurityContext{},
SchedulerName: osdProps.schedulerName,
},
}
+1
View File
@@ -43,6 +43,7 @@ func (r *ReconcileCephRBDMirror) makeDeployment(daemonConfig *daemonConfig, rbdM
Volumes: controller.DaemonVolumes(daemonConfig.DataPathMap, daemonConfig.ResourceName, r.cephClusterSpec.DataDirHostPath),
HostNetwork: r.cephClusterSpec.Network.IsHost(),
PriorityClassName: rbdMirror.Spec.PriorityClassName,
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
+1
View File
@@ -129,6 +129,7 @@ func (c *ResourceCleanup) jobTemplateSpec() v1.PodTemplateSpec {
Volumes: volumes,
RestartPolicy: v1.RestartPolicyOnFailure,
PriorityClassName: cephv1.GetCleanupPriorityClassName(c.cluster.Spec.PriorityClassNames),
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
@@ -29,6 +29,7 @@ spec:
spec:
# HostPID is needed to expose the correct process ID network namespace and not the process namespace
hostPID: true
securityContext: {}
serviceAccountName: rook-csi-cephfs-plugin-sa
{{ if .PluginPriorityClassName }}
priorityClassName: {{ .PluginPriorityClassName }}
@@ -17,6 +17,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-cephfs-provisioner-sa
{{ if .ProvisionerPriorityClassName }}
priorityClassName: {{ .ProvisionerPriorityClassName }}
@@ -22,6 +22,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-cephfs-plugin-sa
hostNetwork: {{ .EnableCSIHostNetwork }}
{{ if .PluginPriorityClassName }}
@@ -29,6 +29,7 @@ spec:
spec:
# HostPID is needed to expose the correct process ID network namespace and not the process namespace
hostPID: true
securityContext: {}
serviceAccountName: rook-csi-nfs-plugin-sa
{{ if .PluginPriorityClassName }}
priorityClassName: {{ .PluginPriorityClassName }}
@@ -16,6 +16,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-nfs-provisioner-sa
{{ if .ProvisionerPriorityClassName }}
priorityClassName: {{ .ProvisionerPriorityClassName }}
@@ -17,6 +17,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-nfs-plugin-sa
hostNetwork: {{ .EnableCSIHostNetwork }}
{{ if .PluginPriorityClassName }}
@@ -29,6 +29,7 @@ spec:
spec:
# HostPID is needed to expose the correct process ID network namespace and not the process namespace
hostPID: true
securityContext: {}
serviceAccountName: rook-csi-rbd-plugin-sa
{{ if .PluginPriorityClassName }}
priorityClassName: {{ .PluginPriorityClassName }}
@@ -17,6 +17,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-rbd-provisioner-sa
{{ if .ProvisionerPriorityClassName }}
priorityClassName: {{ .ProvisionerPriorityClassName }}
@@ -22,6 +22,7 @@ spec:
{{ $key }}: "{{ $value }}"
{{ end }}
spec:
securityContext: {}
serviceAccountName: rook-csi-rbd-plugin-sa
{{ if .PluginPriorityClassName }}
priorityClassName: {{ .PluginPriorityClassName }}
+1
View File
@@ -65,6 +65,7 @@ func (c *Cluster) makeDeployment(mdsConfig *mdsConfig, fsNamespacedname types.Na
Volumes: controller.DaemonVolumes(mdsConfig.DataPathMap, mdsConfig.ResourceName, c.clusterSpec.DataDirHostPath),
HostNetwork: c.clusterSpec.Network.IsHost(),
PriorityClassName: c.fs.Spec.MetadataServer.PriorityClassName,
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
+1
View File
@@ -46,6 +46,7 @@ func (r *ReconcileFilesystemMirror) makeDeployment(daemonConfig *daemonConfig, f
Volumes: controller.DaemonVolumes(daemonConfig.DataPathMap, daemonConfig.ResourceName, r.cephClusterSpec.DataDirHostPath),
HostNetwork: r.cephClusterSpec.Network.IsHost(),
PriorityClassName: fsMirror.Spec.PriorityClassName,
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
},
}
+1
View File
@@ -149,6 +149,7 @@ func (r *ReconcileCephNFS) makeDeployment(nfs *cephv1.CephNFS, cfg daemonConfig)
// connecting to the krb server. give all ganesha servers the same hostname so they can all
// use the same krb credentials to auth
Hostname: fmt.Sprintf("%s-%s", nfs.Namespace, nfs.Name),
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
}
// Replace default unreachable node toleration
+1
View File
@@ -88,6 +88,7 @@ func createCOSIPodSpec(cephCOSIDriver *cephv1.CephCOSIDriver) (corev1.PodTemplat
cosiDriverContainer,
cosiSideCarContainer,
},
SecurityContext: &corev1.PodSecurityContext{},
ServiceAccountName: DefaultServiceAccountName,
Volumes: []corev1.Volume{
{Name: cosiSocketVolumeName, VolumeSource: corev1.VolumeSource{EmptyDir: &corev1.EmptyDirVolumeSource{}}},
+1
View File
@@ -150,6 +150,7 @@ func (c *clusterConfig) makeRGWPodSpec(rgwConfig *rgwConfig) (v1.PodTemplateSpec
),
HostNetwork: hostNetwork,
PriorityClassName: c.store.Spec.Gateway.PriorityClassName,
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: serviceAccountName,
}
+1
View File
@@ -177,6 +177,7 @@ func (d *Discover) createDiscoverDaemonSet(ctx context.Context, namespace, disco
},
HostNetwork: opcontroller.EnforceHostNetwork(),
PriorityClassName: k8sutil.GetValue(data, discoverDaemonsetPriorityClassNameEnv, ""),
SecurityContext: &v1.PodSecurityContext{},
},
},
},
@@ -302,6 +302,7 @@ func (cr *cmdReporterCfg) initJobSpec() (*batch.Job, error) {
*cmdReporterContainer,
},
RestartPolicy: v1.RestartPolicyOnFailure,
SecurityContext: &v1.PodSecurityContext{},
ServiceAccountName: k8sutil.DefaultServiceAccount,
HostNetwork: cephv1.EnforceHostNetwork(),
}