Skip to content

ROX-33932: Disable allowPrivilegeEscalation#2648

Merged
kurlov merged 1 commit intomainfrom
akurlov/ROX-33932-disable-allowPrivilegeEscalation
Apr 2, 2026
Merged

ROX-33932: Disable allowPrivilegeEscalation#2648
kurlov merged 1 commit intomainfrom
akurlov/ROX-33932-disable-allowPrivilegeEscalation

Conversation

@kurlov
Copy link
Copy Markdown
Member

@kurlov kurlov commented Apr 1, 2026

Description

To mitigate Container with privilege escalation allowed violation from dogfooding.

Basically, when allowPrivilegeEscalation is not explicitly set to false, Kubernetes defaults to allowing privilege escalation

Both services do not need allowPrivilegeEscalation permission

@openshift-ci
Copy link
Copy Markdown
Contributor

openshift-ci bot commented Apr 1, 2026

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: kovayur, kurlov

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kurlov kurlov merged commit cb5eba3 into main Apr 2, 2026
16 checks passed
@kurlov kurlov deleted the akurlov/ROX-33932-disable-allowPrivilegeEscalation branch April 2, 2026 11:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants