feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat: secure-pod-defaults is enabled by default - #14168

Closed
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled
Closed

feat: secure-pod-defaults is enabled by default#14168
kauana wants to merge 6 commits into
knative:mainfrom
kauana:secure-pod-defaults-enabled

Conversation

@kauana

@kauanakauana commented Jul 11, 2023

Copy link
Copy Markdown

Fixes#14029

Proposed Changes

  • secure-pod-defaults is now enabled by default on the config-features ConfigMap

@knative-prowknative-prowBot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jul 11, 2023
@knative-prow
knative-prowBot requested review from ReToCode and krsna-mJuly 11, 2023 18:32
@kauanakauana changed the title secure-pod-defaults is enabled by default[WIP] secure-pod-defaults is enabled by defaultJul 11, 2023
@knative-prowknative-prowBot added do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. area/API API objects and controllers labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from f5e91db to c8063c3CompareJuly 11, 2023 22:56
@knative-prowknative-prowBot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Jul 11, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 3 times, most recently from e680a43 to faa0f31CompareJuly 12, 2023 01:17
@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 18474ca to bc94f59CompareJuly 12, 2023 06:17
@knative-prowknative-prowBot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. labels Jul 12, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from a65102f to 590813dCompareJuly 12, 2023 15:44
@kauanakauana changed the title [WIP] secure-pod-defaults is enabled by default[WIP] feat: secure-pod-defaults is enabled by defaultJul 14, 2023
@kauana

Copy link
Copy Markdown
Author

Hello @psschwei,

I'm working on updating the tests to account for enabling the flag secure-pod-defaults to true by default (follow up to PR #13398). One failing unit test in particular made me think about the interaction between the two flags SecurePodDefaults and PodSpecSecurityContext. While I'm trying to ramp on these changes, I noticed you mentioned having validation issues when you set SecurePodDefaults: enabled which required enabling PodSpecSecurityContext as well.

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

@psschwei

Copy link
Copy Markdown
Member

Just to recap (and to confirm my own understanding), setting PodSpecSecurityContext allows the user to configure some PodSecurityContext fields mentioned here. However, secure-pod-defaults makes it so pods adhere the restricted pod security standard and it allows some parts of PodSecurityContext to be set but to specific values (including setting allowPrivilegeEscalation to false and seccompProfile to RuntimeDefault).

I think you're right

Anyways, I do see a bit of a conflict between these two flags. Perhaps the flag to set PodSpecSecurityContext is now redundant or when SecurePodDefault is enabled it enables PodSpecSecurityContext by default? I would like to heart your thoughts.

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

cc @evankanderson who also had thoughts on this iirc

@kauana

Copy link
Copy Markdown
Author

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

There might be some scenario where someone doesn't want to use our secure defaults or enable the pod security context, so it may make sense to leave in the PodSpecSecurityContext flag, at least for the time being.

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext? This PR is an attempt at making SecurePodDefaults enabled by default (#14029), which would mean PodSpecSecurityContext would also be enabled by default.

Currently, kubernetes.podspec-securitycontext is set to "disabled" by default, with warnings about enabling this feature flag (see here). So, I'm thinking that before we do this, we might want to add a "warning" similar to what Evan did here?

@psschwei

Copy link
Copy Markdown
Member

I'm wondering what should be the timeline for making SecurePodDefaults enable PodSpecSecurityContext?

I think you'd need to do that for this PR, but I'd keep both flags (so that a user could toggle them both off if they so desired).

@dprotaso

dprotaso commented Jul 31, 2023

Copy link
Copy Markdown
Member

I think the latter option (SecurePodDefault enabled also enables PodSpecSecurityContext) makes sense for now.

We shouldn't do this.

SecurePodDefault should only allow the desired defaults to be set to specific values

Enabling PodSpecSecurityContext gives users way more freedom than SecurePodDefaults intends

@KauzClay

KauzClay commented Sep 13, 2023

Copy link
Copy Markdown
Contributor

perhaps the changes in #14363

could be rolled into this PR as well

OR

The test updates and stuff get rolled into #14363 , and this PR just becomes changing the default.

That way we could backport the other changes

@dprotaso

Copy link
Copy Markdown
Member

If #14363 means secure pod defaults is broken when enabled then we should fix it (and I'll cherry-pick it)

I think the scope of this PR should just remain to flipping secure pod defaults from off to on

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 590813d to 58c5e7eCompareSeptember 20, 2023 17:54
@knative-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kauana
Once this PR has been reviewed and has the lgtm label, please assign davidhadas for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@knative-prowknative-prowBot added size/XL Denotes a PR that changes 500-999 lines, ignoring generated files. and removed size/L Denotes a PR that changes 100-499 lines, ignoring generated files. labels Sep 21, 2023
@codecov

codecovBot commented Sep 26, 2023

Copy link
Copy Markdown

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (05e349f) 86.11% compared to head (a3204f1) 86.12%.
Report is 153 commits behind head on main.

Additional details and impacted files
@@ Coverage Diff @@## main #14168 +/- ##
==========================================
+ Coverage 86.11% 86.12% +0.01% 
==========================================
Files 196 196 Lines 14880 14880 ==========================================
+ Hits 12814 12816 +2 + Misses 1758 1754 -4 - Partials 308 310 +2 

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from bae5bb4 to 97d080dCompareSeptember 26, 2023 21:04
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch 2 times, most recently from 3b76307 to 76f9f52CompareSeptember 29, 2023 00:45
@kauana

Copy link
Copy Markdown
Author

/retest

@kauanakauana changed the title [WIP] feat: secure-pod-defaults is enabled by defaultfeat: secure-pod-defaults is enabled by defaultSep 29, 2023
@knative-prowknative-prowBot removed the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Sep 29, 2023
- Secure pod default off and podspec security context off ..can't set special securitycontext properties
- Secure pod default off and podspec security context on...can change allowed securitycontext to anything, e.g. runAsNonRoot: false
- Secure pod default on and podspec security context off...must use restricted profile security properties
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 76f9f52 to 8b51a60CompareSeptember 29, 2023 05:13
@dprotaso

Copy link
Copy Markdown
Member

/retest

@knative-prowknative-prowBot added the area/test-and-release It flags unit/e2e/conformance/perf test issues for product features label Sep 29, 2023
@kauana
kauanaforce-pushed the secure-pod-defaults-enabled branch from 8239a07 to a3204f1CompareSeptember 29, 2023 16:25
@knative-prow

Copy link
Copy Markdown

@kauana: The following test failed, say /retest to rerun all failed tests or /retest-required to rerun all mandatory failed tests:

Test nameCommitDetailsRequiredRerun command
upgrade-tests_serving_maina3204f1linktrue/test upgrade-tests

Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@dprotaso

Copy link
Copy Markdown
Member

/hold

see: #14029 (comment)

@knative-prowknative-prowBot added the do-not-merge/hold Indicates that a PR should not merge because someone has issued a /hold command. label Sep 29, 2023
@github-actions

Copy link
Copy Markdown

This Pull Request is stale because it has been open for 90 days with
no activity. It will automatically close after 30 more days of
inactivity. Reopen with /reopen. Mark as fresh by adding the
comment /remove-lifecycle stale.

@github-actionsgithub-actionsBot added the lifecycle/stale Denotes an issue or PR has remained open with no activity and has become stale. label Dec 29, 2023
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/APIAPI objects and controllersarea/test-and-releaseIt flags unit/e2e/conformance/perf test issues for product featuresdo-not-merge/holdIndicates that a PR should not merge because someone has issued a /hold command.lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.size/XLDenotes a PR that changes 500-999 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Set secure-pod-defaults to "enabled" by default

4 participants

@kauana@psschwei@dprotaso@KauzClay