Skip to content

Commit 9bebbd1

Browse files
committed
Improve Security Context of Node Server Container
Signed-off-by: Ambika Nair <[email protected]>
1 parent 8872a1e commit 9bebbd1

File tree

1 file changed

+7
-6
lines changed

1 file changed

+7
-6
lines changed

controllers/syncer/csi_node.go

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -127,14 +127,12 @@ func (s *csiNodeSyncer) ensureContainersSpec() []corev1.Container {
127127
})
128128

129129
nodePlugin.SecurityContext = &corev1.SecurityContext{
130-
RunAsNonRoot: util.False(),
131-
Privileged: util.True(),
132-
AllowPrivilegeEscalation: util.True(),
133-
RunAsUser: func(uid int64) *int64 { return &uid }(0),
130+
RunAsNonRoot: util.False(),
131+
Privileged: util.True(),
132+
RunAsUser: func(uid int64) *int64 { return &uid }(0),
134133
}
135134
fillSecurityContextCapabilities(
136135
nodePlugin.SecurityContext,
137-
"SYS_ADMIN",
138136
)
139137

140138
// node driver registrar sidecar
@@ -162,7 +160,10 @@ func (s *csiNodeSyncer) ensureContainersSpec() []corev1.Container {
162160
healthPortArg,
163161
},
164162
)
165-
livenessProbe.SecurityContext = &corev1.SecurityContext{AllowPrivilegeEscalation: util.False()}
163+
livenessProbe.SecurityContext = &corev1.SecurityContext{RunAsNonRoot: util.False(),
164+
RunAsUser: func(uid int64) *int64 { return &uid }(0),
165+
Privileged: util.False(),
166+
}
166167
fillSecurityContextCapabilities(livenessProbe.SecurityContext)
167168
livenessProbe.ImagePullPolicy = s.getCSINodeDriverRegistrarPullPolicy()
168169
livenessProbe.Resources = getSidecarResourceRequests(s.driver, constants.LivenessProbe)

0 commit comments

Comments
 (0)