Skip to content

Setup additional hardening for pods#168

Merged
1602077 merged 2 commits intocvmfs-contrib:masterfrom
jcpunk:harden-pods
Feb 6, 2026
Merged

Setup additional hardening for pods#168
1602077 merged 2 commits intocvmfs-contrib:masterfrom
jcpunk:harden-pods

Conversation

@jcpunk
Copy link
Contributor

@jcpunk jcpunk commented Jan 16, 2026

This PR adds a number of security hardening best practices to the cvmfs plugins.

hostUsers seems to require the ability to chown the filesystem, which is a non-starter.

The acutal mount bits all require system privileges, so they can't be locked down much further.

jcpunk and others added 2 commits January 16, 2026 13:24
@1602077
Copy link
Collaborator

1602077 commented Feb 6, 2026

@jcpunk Thank you for this and the other related PRs over the last few weeks!

Apologies I missed them in my inbox. I will release a rc version today to test and validate that includes these fixes and then tag the official candidate for you early next week.

Cheers,
Jack

@1602077 1602077 merged commit 0a591f7 into cvmfs-contrib:master Feb 6, 2026
2 checks passed
@jcpunk jcpunk deleted the harden-pods branch February 6, 2026 14:03
@jcpunk
Copy link
Contributor Author

jcpunk commented Feb 6, 2026

Sounds good, I think I closed out some of the github issues, but they didn't link up?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants