Skip to content

Add capabilities and create user to enable security hardening#681

Open
ljkiraly wants to merge 1 commit intonetworkservicemesh:mainfrom
Nordix:docker-cap
Open

Add capabilities and create user to enable security hardening#681
ljkiraly wants to merge 1 commit intonetworkservicemesh:mainfrom
Nordix:docker-cap

Conversation

@ljkiraly
Copy link
Copy Markdown
Contributor

Signed-off-by: Laszlo Kiraly laszlo.kiraly@est.tech

@denis-tingaikin
Copy link
Copy Markdown
Member

Woot!

@ljkiraly Is this PR allows to cut secureContext: privileged: true from forwarder deployment?

@ljkiraly
Copy link
Copy Markdown
Contributor Author

@denis-tingaikin No, the secureContext: privileged: true still needed :( . Just enables to run the forwarder and vpp as non root and to drop any unused privilege.

Signed-off-by: Laszlo Kiraly <laszlo.kiraly@est.tech>
nsmbot pushed a commit that referenced this pull request Jan 23, 2023
…k-vpp@main

PR link: networkservicemesh/sdk-vpp#681

Commit: 1991351
Author: Ruslan Bayandinov
Date: 2023-01-23 15:32:41 +0700
Message:
  - Fix deprecated Github Action set-output (#681)
Signed-off-by: Ruslan Bayandinov <wazsone@ya.ru>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
Copy link
Copy Markdown
Member

@denis-tingaikin denis-tingaikin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@edwarnicke WDYT?

nsmbot pushed a commit that referenced this pull request Sep 27, 2024
…k-vpp@main

PR link: networkservicemesh/sdk-vpp#853

Commit: 0702bd9
Author: Network Service Mesh Bot
Date: 2024-09-27 05:48:04 -0500
Message:
  - Update go.mod and go.sum to latest version from networkservicemesh/sdk-kernel@main (#853)
PR link: networkservicemesh/sdk-kernel#681
Commit: 19add25
Author: Network Service Mesh Bot
Date: 2024-09-27 05:44:16 -0500
Message:
    - Update go.mod and go.sum to latest version from networkservicemesh/sdk@main (#681)
PR link: networkservicemesh/sdk#1670
Commit: b66e1bf
Author: Nikita Skrynnik
Date: 2024-09-27 17:37:34 +0700
Message:
        - Add more mutexes in dial chain element to fix race conditions (#1670)
* some minor change
* add more locks
---------
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit that referenced this pull request Sep 27, 2024
…k-sriov@main

PR link: networkservicemesh/sdk-sriov#610

Commit: e12f4c8
Author: Network Service Mesh Bot
Date: 2024-09-27 05:48:41 -0500
Message:
  - Update go.mod and go.sum to latest version from networkservicemesh/sdk-kernel@main (#610)
PR link: networkservicemesh/sdk-kernel#681
Commit: 19add25
Author: Network Service Mesh Bot
Date: 2024-09-27 05:44:16 -0500
Message:
    - Update go.mod and go.sum to latest version from networkservicemesh/sdk@main (#681)
PR link: networkservicemesh/sdk#1670
Commit: b66e1bf
Author: Nikita Skrynnik
Date: 2024-09-27 17:37:34 +0700
Message:
        - Add more mutexes in dial chain element to fix race conditions (#1670)
* some minor change
* add more locks
---------
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants