Skip to content

feat(operator): Add security context defaults - #1292

Open
lfrancke wants to merge 1 commit into
mainfrom
feat/security-context-defaults
Open

lfrancke wants to merge 1 commit into
mainfrom
feat/security-context-defaults

Conversation

@lfrancke

@lfrancke lfrancke commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Part of stackabletech/issues#645

The with_stackable_defaults builders now set what the restricted Pod Security Standard asks for.
OpenShift's SCCs have been injecting exactly these for years, so nothing changes there and I'm fairly confident it's safe. On non-OpenShift Kubernetes a namespace enforcing restricted currently rejects our Pods. I tested that on k3d for the operator Deployments (not for the products but I'd expect the same there)

Every operator already calls PodSecurityContextBuilder::with_stackable_defaults, so the seccomp part only needs an operator-rs bump. The container part only kicks in once operators use SecurityContextBuilder for each container, which none do yet. That'll be a follow-up.

This makes our containers compliant with the "restricted" Pod Security Standard and any admission policies that require it.

OpenShift already injects these today (and has done so in the past) so that's why I'm pretty certain our operators & products can deal with these.
@lfrancke lfrancke self-assigned this Oct 3, 2026
@lfrancke
lfrancke marked this pull request as ready for review October 3, 2026 21:37

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Development: Waiting for Review

Development

Successfully merging this pull request may close these issues.

1 participant