Add "NET_RAW" to ironic-endpoint-keepalived#782
Add "NET_RAW" to ironic-endpoint-keepalived#782metal3-io-bot merged 1 commit intometal3-io:masterfrom
Conversation
|
Hi @Insullone. Thanks for your PR. I'm waiting for a metal3-io member to verify that this patch is reasonable to test. If it is, they should reply with Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
/test/integration |
|
lgtm |
|
/test-integration |
|
/lgtm |
|
@Xenwar: adding LGTM is restricted to approvers and reviewers in OWNERS files. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. |
|
LGTM. |
|
/ok-to-test |
|
/lgtm |
furkatgofurov7
left a comment
There was a problem hiding this comment.
Not a blocker though, question inline:
| securityContext: | ||
| capabilities: | ||
| add: ["NET_ADMIN"] | ||
| add: ["NET_ADMIN", "NET_RAW"] |
There was a problem hiding this comment.
Is there any other alternative to avoid adding this capability in order to fix the issue with ironic-endpoint? The reason I was curious is mainly that this might be a security flaw.
There was a problem hiding this comment.
@furkatgofurov7 I am having difficulty understanding how adding these two capabilities is a security flaw, Yes you should not add these capabilities to untrusted containers, but for your own trusted containers, if you dont add them and if your container needs them, it will simply not work.
There was a problem hiding this comment.
Okay, I was not sure, if this is in the context of untrusted containers, my understanding was, it can be any container.
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: Insullone, maelk The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
The capability 'NET_RAW' is needed to open a raw socket in ironic-endpoint-keepalived otherwise the container will fail.