Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

bug(helm): certgen hook is rejected by Restricted Pod Security

Aperta
#3,215 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
74/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
helm, kubernetes

Direzione di ricerca

Inizia con il template del chart Helm di OpenShell che esegue il rendering del certgen Job e confrontalo con i security context configurabili del pod e del container del gateway. Esegui helm template usando le impostazioni di riproduzione, quindi esamina i test del chart. Il lavoro è completo quando l’hook renderizzato per impostazione predefinita supera Restricted admission, espone override specifici per certgen ed è coperto da test senza richiedere una migrazione per le installazioni esistenti.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

state:accepted

User Story

As a Kubernetes platform operator enforcing the Restricted Pod Security Standard on controller namespaces, I want the OpenShell Helm chart's certificate-generation hook to pass admission, so that I can install the gateway without weakening the namespace security policy.

Problem Statement

OpenShell Helm chart 0.0.116 renders Job/<release>-certgen without a pod securityContext and without runAsNonRoot or seccompProfile on its container. The container already drops all capabilities and disables privilege escalation, but Kubernetes Restricted Pod Security admission still rejects the hook for the missing non-root and seccomp settings.

The main gateway workload can already be configured with podSecurityContext and securityContext; the certgen hook does not inherit those settings and exposes no equivalent values.

Impact / Why This Matters

The pre-install/pre-upgrade hook blocks the entire Helm release in a namespace labeled pod-security.kubernetes.io/enforce: restricted. Operators must either weaken admission for the trusted gateway namespace or carry a Flux/Helm post-render patch for a security-sensitive hook. The post-render workaround is coupled to the hook resource name and container position and can silently stop matching after a chart refactor unless it is separately tested.

Acceptance Criteria

  • A default helm template render of the certgen Job satisfies the Restricted Pod Security Standard for the chart's supported Kubernetes versions.
  • The certgen pod and container run as non-root and declare a Restricted-compatible seccomp profile.
  • The chart exposes certgen-specific pod/container security-context values if operators need to override the defaults.
  • Chart tests cover the rendered certgen security context.
  • Existing installs that do not enforce Pod Security continue to upgrade without manual migration.

Reproduction Steps

  1. Create a namespace with pod-security.kubernetes.io/enforce: restricted (tested with policy version v1.36).
  2. Install OpenShell chart 0.0.116 with Agent Sandbox available and pkiInitJob.enabled: true.
  3. Observe that Job/<release>-certgen is rejected by Pod Security admission for missing runAsNonRoot and seccompProfile fields.
  4. Render the chart and compare the certgen Job with the configurable gateway StatefulSet security contexts.

Environment

  • OpenShell Helm chart: 0.0.116, OCI digest sha256:df55cd1538bdfb7836834c30dfcf8373b85ffea83bbfd70d50dbe69407a0d2b3
  • Kubernetes: v1.36.4
  • Distribution: Talos Linux v1.13.9
  • Deployment: Flux HelmRelease, Kubernetes Agent Sandbox driver

Logs

The rendered certgen container has allowPrivilegeEscalation: false and drops ALL, but neither the pod nor container declares runAsNonRoot or seccompProfile. Restricted admission reports those missing fields under the restricted policy.

Lingua principale
Rust
Stelle
8.7k
Fork
1.3k
Merge medio
2g 6h
PR unite (30g)
297

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di NVIDIA/OpenShell

Tutte le issue di NVIDIA/OpenShell

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.