4 ms·
Does RBAC not limit these by default? Does cert-manger not already give itself restricted permission on install? Do I need to fix up my cluster right now? If so
by ipodopt 6y ago
Does RBAC not limit these by default? Does cert-manger not already give itself restricted permission on install? Do I need to fix up my cluster right now? If so, do you have any example RBAC yamls? :D
> And when building docker images in the CI, I use google’s kaniko to build docker images from within docker without any privileges (it unpacks docker images for building and runs them inside the existing container, basically just chroot).
You can also use standalone buildkit which comes with the added benefit of being able to use the same builder locally natively.
- threentaway 6y agoNo RBAC doesn't automatically do this. And many publicly available Helm charts are missing these basic security configurations. You should use Gatekeeper or similar to enforce these settings throughout your cluster.
- westurner 6y agoGatekeeper docs: https://open-policy-agent.github.io/gatekeeper/website/docs/ https://open-policy-agent.github.io/gatekeeper/website/docs/ Gatekeeper src: https://github.com/open-policy-agent/gatekeeper https://github.com/open-policy-agent/gatekeeper awesome-container-security: https://github.com/kai5263499/awesome-container-security https://github.com/kai5263499/awesome-container-security "container-security" GitHub label: https://github.com/topics/container-security https://github.com/topics/container-security
- rhizome 6y agoEveryday DevOps strays further from SysAdmin's light.