Skip to content

Conversation

jakogut
Copy link
Contributor

@jakogut jakogut commented Jan 31, 2024

No description provided.

Removes the automatic population of host devices at container startup,
and replaces privileged with fine(r) grained capabilities.

Change-type: patch
Signed-off-by: Joseph Kogut <[email protected]>
Binding the host's devtmpfs inside a container, especially in
combination with `privileged: true` has a high likelyhood of tampering
with host device permissions and nodes. Remove it.

Change-type: patch
Signed-off-by: Joseph Kogut <[email protected]>
@jakogut jakogut force-pushed the remove-unnecessary-permissions branch from b55c71f to 5d13217 Compare January 31, 2024 21:15
@jakogut
Copy link
Contributor Author

jakogut commented Jan 31, 2024

Passes the OS suite, but fails preloading. Marking as a draft again.

@jakogut jakogut marked this pull request as draft January 31, 2024 21:39
auto-merge was automatically disabled January 31, 2024 21:39

Pull request was converted to draft

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant