Skip to content

Commit 08cf4e2

Browse files
lmicciniclaude
andcommitted
Harden Redis, InstanceHA, Memcached, and DNSMasq workload security
Address anyuid SCC and overly permissive RBAC findings across all infra-operator workloads except RabbitMQ. Redis: - Reduce workload SA pod verbs from full CRUD to get/list/watch/patch (only PATCH is used by common.sh for pod label operations) - Add SecurityContext (RunAsUser/RunAsGroup/RunAsNonRoot) - Add SeccompProfile RuntimeDefault - Set AutomountServiceAccountToken: false with projected SA token volume - SCC remains anyuid (sudo -E kolla_set_configs blocks nonroot-v2) InstanceHA: - Change SCC from anyuid to nonroot-v2 - Add SeccompProfile RuntimeDefault - Set AutomountServiceAccountToken: false with projected SA token volume - Use lib-common pod.RestrictiveSecurityContext helper Memcached: - Change SCC from anyuid to nonroot-v2 - Remove full pod CRUD from workload SA (no SA token usage) - Set AutomountServiceAccountToken: false - Add full SecurityContext via pod.RestrictiveSecurityContext helper (RunAsNonRoot, AllowPrivilegeEscalation: false, Drop ALL, SeccompProfile) DNSMasq: - Change SCC from anyuid to nonroot-v2 - Remove full pod CRUD from workload SA (no SA token usage) - Set AutomountServiceAccountToken: false - Add DnsmasqUID constant (42435, neutron UID from kolla) - Add RunAsUser/RunAsGroup and Capabilities.Drop ALL via pod.RestrictiveSecurityContext helper Depends-On: openstack-k8s-operators/lib-common#720 Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent b5154b6 commit 08cf4e2

18 files changed

Lines changed: 267 additions & 89 deletions

File tree

apis/go.mod

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -70,6 +70,8 @@ require (
7070

7171
replace github.com/openshift/api => github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4 //allow-merging
7272

73+
replace github.com/openstack-k8s-operators/lib-common/modules/common => github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a //allow-merging
74+
7375
// pin these to avoid later versions pulled
7476
replace k8s.io/apimachinery => k8s.io/apimachinery v0.33.13 //allow-merging
7577

apis/go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,8 @@ github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
6464
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
6565
github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc=
6666
github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw=
67+
github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a h1:j+CcLvhJPj9aEc++PW/SR227JigGl42gRgDW2q3en/0=
68+
github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a/go.mod h1:yA4tbcB62Dml5d0SP3n14hbwLVrKFicm690/eTWvusc=
6769
github.com/mailru/easyjson v0.9.0 h1:PrnmzHw7262yW8sTBwxi1PdJA3Iw/EKBa8psRf7d9a4=
6870
github.com/mailru/easyjson v0.9.0/go.mod h1:1+xMtQp2MRNVL/V1bOzuP3aP8VNwRW55fQUto+XFtTU=
6971
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
@@ -81,8 +83,6 @@ github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
8183
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
8284
github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4 h1:YVY7Mb0AdJBbNgC/Zz9R/ZwhixOmZNA8P+6ZPaDW/0M=
8385
github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4/go.mod h1:SPLf21TYPipzCO67BURkCfK6dcIIxx0oNRVWaOyRcXM=
84-
github.com/openstack-k8s-operators/lib-common/modules/common v0.6.1-0.20260717092345-ab1ee7b97c67 h1:crgFl4DA5n38huc043ux21jEQM7UaRMXsi+wogDOYn0=
85-
github.com/openstack-k8s-operators/lib-common/modules/common v0.6.1-0.20260717092345-ab1ee7b97c67/go.mod h1:yA4tbcB62Dml5d0SP3n14hbwLVrKFicm690/eTWvusc=
8686
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
8787
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
8888
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=

config/rbac/role.yaml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,6 +350,14 @@ rules:
350350
- securitycontextconstraints
351351
verbs:
352352
- use
353+
- apiGroups:
354+
- security.openshift.io
355+
resourceNames:
356+
- nonroot-v2
357+
resources:
358+
- securitycontextconstraints
359+
verbs:
360+
- use
353361
- apiGroups:
354362
- topology.openstack.org
355363
resources:

go.mod

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -109,6 +109,8 @@ require (
109109

110110
replace github.com/openstack-k8s-operators/infra-operator/apis => ./apis
111111

112+
replace github.com/openstack-k8s-operators/lib-common/modules/common => github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a //allow-merging
113+
112114
// mschuppert: map to latest commit from release-4.20 tag
113115
// must consistent within modules and service operators
114116
replace github.com/openshift/api => github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4 //allow-merging

go.sum

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,8 @@ github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
9494
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
9595
github.com/kylelemons/godebug v1.1.0 h1:RPNrshWIDI6G2gRW9EHilWtl7Z6Sb1BR0xunSBf0SNc=
9696
github.com/kylelemons/godebug v1.1.0/go.mod h1:9/0rRGxNHcop5bhtWyNeEfOS8JIWk580+fNqagV/RAw=
97+
github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a h1:j+CcLvhJPj9aEc++PW/SR227JigGl42gRgDW2q3en/0=
98+
github.com/lmiccini/lib-common/modules/common v0.0.0-20260723135709-89117b10db4a/go.mod h1:yA4tbcB62Dml5d0SP3n14hbwLVrKFicm690/eTWvusc=
9799
github.com/mailru/easyjson v0.9.0 h1:PrnmzHw7262yW8sTBwxi1PdJA3Iw/EKBa8psRf7d9a4=
98100
github.com/mailru/easyjson v0.9.0/go.mod h1:1+xMtQp2MRNVL/V1bOzuP3aP8VNwRW55fQUto+XFtTU=
99101
github.com/maruel/natural v1.1.1 h1:Hja7XhhmvEFhcByqDoHz9QZbkWey+COd9xWfCfn1ioo=
@@ -116,8 +118,6 @@ github.com/onsi/gomega v1.42.1 h1:iN1rCUX+44NZ1Dc97MPoeFYbFR0vh8zxoxMFwKdyZ6I=
116118
github.com/onsi/gomega v1.42.1/go.mod h1:REff/hsDsodHoKlWsP2mAPhu1+5/6hVYNf9rIEBpeSg=
117119
github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4 h1:YVY7Mb0AdJBbNgC/Zz9R/ZwhixOmZNA8P+6ZPaDW/0M=
118120
github.com/openshift/api v0.0.0-20260710141509-36dec0bfafe4/go.mod h1:SPLf21TYPipzCO67BURkCfK6dcIIxx0oNRVWaOyRcXM=
119-
github.com/openstack-k8s-operators/lib-common/modules/common v0.6.1-0.20260717092345-ab1ee7b97c67 h1:crgFl4DA5n38huc043ux21jEQM7UaRMXsi+wogDOYn0=
120-
github.com/openstack-k8s-operators/lib-common/modules/common v0.6.1-0.20260717092345-ab1ee7b97c67/go.mod h1:yA4tbcB62Dml5d0SP3n14hbwLVrKFicm690/eTWvusc=
121121
github.com/openstack-k8s-operators/lib-common/modules/edpm v0.0.0-20260717092345-ab1ee7b97c67 h1:EoBTLbbfGRC37uA0J6al5zeZfQSxy6XwsUMNZAWCQPA=
122122
github.com/openstack-k8s-operators/lib-common/modules/edpm v0.0.0-20260717092345-ab1ee7b97c67/go.mod h1:IN0pCq/v2MsPcXrtcBIqcpVEqyq8oTIbNahmsc3tu28=
123123
github.com/openstack-k8s-operators/lib-common/modules/test v0.6.1-0.20260717092345-ab1ee7b97c67 h1:GmakXxpm0scnNPuFDC9fSdhqo8MPyyBqqL0UW8pNh5o=

internal/controller/instanceha/instanceha_controller.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -95,7 +95,7 @@ func (r *Reconciler) GetLogger(ctx context.Context) logr.Logger {
9595
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=roles,verbs=get;list;watch;create;update;patch
9696
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=rolebindings,verbs=get;list;watch;create;update;patch
9797
// service account permissions that are needed to grant permission to the above
98-
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=anyuid,resources=securitycontextconstraints,verbs=use
98+
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=nonroot-v2,resources=securitycontextconstraints,verbs=use
9999
// +kubebuilder:rbac:groups="",resources=pods,verbs=get;list;watch
100100
// +kubebuilder:rbac:groups="",resources=events,verbs=create;patch
101101
// +kubebuilder:rbac:groups=topology.openstack.org,resources=topologies,verbs=get;list;watch;update
@@ -205,7 +205,7 @@ func (r *Reconciler) Reconcile(ctx context.Context, req ctrl.Request) (result ct
205205
rbacRules := []rbacv1.PolicyRule{
206206
{
207207
APIGroups: []string{"security.openshift.io"},
208-
ResourceNames: []string{"anyuid"},
208+
ResourceNames: []string{"nonroot-v2"},
209209
Resources: []string{"securitycontextconstraints"},
210210
Verbs: []string{"use"},
211211
},

internal/controller/memcached/memcached_controller.go

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -103,8 +103,7 @@ func (r *Reconciler) GetLogger(ctx context.Context) logr.Logger {
103103
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=roles,verbs=get;list;watch;create;update;patch
104104
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=rolebindings,verbs=get;list;watch;create;update;patch
105105
// service account permissions that are needed to grant permission to the above
106-
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=anyuid,resources=securitycontextconstraints,verbs=use
107-
// +kubebuilder:rbac:groups="",resources=pods,verbs=create;delete;get;list;patch;update;watch
106+
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=nonroot-v2,resources=securitycontextconstraints,verbs=use
108107
// +kubebuilder:rbac:groups=topology.openstack.org,resources=topologies,verbs=get;list;watch;update
109108

110109
// Reconcile - Memcached
@@ -225,15 +224,10 @@ func (r *Reconciler) Reconcile(ctx context.Context, req ctrl.Request) (result ct
225224
rbacRules := []rbacv1.PolicyRule{
226225
{
227226
APIGroups: []string{"security.openshift.io"},
228-
ResourceNames: []string{"anyuid"},
227+
ResourceNames: []string{"nonroot-v2"},
229228
Resources: []string{"securitycontextconstraints"},
230229
Verbs: []string{"use"},
231230
},
232-
{
233-
APIGroups: []string{""},
234-
Resources: []string{"pods"},
235-
Verbs: []string{"create", "get", "list", "watch", "update", "patch", "delete"},
236-
},
237231
}
238232
rbacResult, err := common_rbac.ReconcileRbac(ctx, helper, instance, rbacRules)
239233
if err != nil {

internal/controller/network/dnsmasq_controller.go

Lines changed: 2 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -97,8 +97,7 @@ func (r *DNSMasqReconciler) GetLogger(ctx context.Context) logr.Logger {
9797
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=roles,verbs=get;list;watch;create;update;patch
9898
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=rolebindings,verbs=get;list;watch;create;update;patch
9999
// service account permissions that are needed to grant permission to the above
100-
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=anyuid,resources=securitycontextconstraints,verbs=use
101-
// +kubebuilder:rbac:groups="",resources=pods,verbs=create;delete;get;list;patch;update;watch
100+
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=nonroot-v2,resources=securitycontextconstraints,verbs=use
102101
// +kubebuilder:rbac:groups=topology.openstack.org,resources=topologies,verbs=get;list;watch;update
103102

104103
// Reconcile is part of the main kubernetes reconciliation loop which aims to
@@ -205,15 +204,10 @@ func (r *DNSMasqReconciler) Reconcile(ctx context.Context, req ctrl.Request) (re
205204
rbacRules := []rbacv1.PolicyRule{
206205
{
207206
APIGroups: []string{"security.openshift.io"},
208-
ResourceNames: []string{"anyuid"},
207+
ResourceNames: []string{"nonroot-v2"},
209208
Resources: []string{"securitycontextconstraints"},
210209
Verbs: []string{"use"},
211210
},
212-
{
213-
APIGroups: []string{""},
214-
Resources: []string{"pods"},
215-
Verbs: []string{"create", "get", "list", "watch", "update", "patch", "delete"},
216-
},
217211
}
218212
rbacResult, err := common_rbac.ReconcileRbac(ctx, helper, instance, rbacRules)
219213
if err != nil {

internal/controller/redis/redis_controller.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -107,7 +107,7 @@ type Reconciler struct {
107107
// +kubebuilder:rbac:groups="rbac.authorization.k8s.io",resources=rolebindings,verbs=get;list;watch;create;update
108108
// service account permissions that are needed to grant permission to the above
109109
// +kubebuilder:rbac:groups="security.openshift.io",resourceNames=anyuid,resources=securitycontextconstraints,verbs=use
110-
// +kubebuilder:rbac:groups="",resources=pods,verbs=create;delete;get;list;patch;update;watch
110+
// +kubebuilder:rbac:groups="",resources=pods,verbs=get;list;patch;watch
111111
// +kubebuilder:rbac:groups=topology.openstack.org,resources=topologies,verbs=get;list;watch;update
112112

113113
// Reconcile - Redis
@@ -219,7 +219,7 @@ func (r *Reconciler) Reconcile(ctx context.Context, req ctrl.Request) (result ct
219219
{
220220
APIGroups: []string{""},
221221
Resources: []string{"pods"},
222-
Verbs: []string{"create", "get", "list", "watch", "update", "patch", "delete"},
222+
Verbs: []string{"get", "list", "watch", "patch"},
223223
},
224224
}
225225
rbacResult, err := common_rbac.ReconcileRbac(ctx, helper, instance, rbacRules)

internal/dnsmasq/const.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,4 +24,7 @@ const (
2424
DNSPort int32 = 53
2525
// DNSTargetPort - port used the service is listening on in the pod
2626
DNSTargetPort int32 = 5353
27+
28+
// DnsmasqUID - https://github.com/openstack/kolla/blob/master/kolla/common/users.py
29+
DnsmasqUID int64 = 42435
2730
)

0 commit comments

Comments
 (0)