Skip to content

NIC should be able to run with the "restricted" POD security level #3544

@hafe

Description

@hafe

WIP

Summary

NIC is currently (3.x) required to run as a privileged POD with added capabilities. This is not ideal from a security perspective and not aligned with best practice container security guidelines and standards such as:

To improve the security posture, NIC should be able to run with the restricted POD security level. See Pod Security Standards for more information.

Motivation

NIC is usually exposed to the Internet and thus a target for all kinds of attacks. The project should always strive to improve the security of NIC.

Goals

  • Secure by default
  • Restricted security level in deployment resources

Non-goals

Proposal

TBD

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs more infoIssues that require more informationstalePull requests/issues with no activity

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions