mirror of
https://github.com/YuzuZensai/netbird-kubernetes-operator.git
synced 2026-09-13 10:49:15 +00:00
Make sidecar profile containers read only by default (#333)
This applies the same changes made to the network router to the sidecar profile container. Majority of users want read only containers so it should be the default. Fixes #312 Fixes #292 Fixes #144
This commit is contained in:
@@ -11,6 +11,7 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
corev1 "k8s.io/api/core/v1"
|
corev1 "k8s.io/api/core/v1"
|
||||||
|
"k8s.io/apimachinery/pkg/api/resource"
|
||||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||||
"k8s.io/apimachinery/pkg/labels"
|
"k8s.io/apimachinery/pkg/labels"
|
||||||
"k8s.io/apimachinery/pkg/types"
|
"k8s.io/apimachinery/pkg/types"
|
||||||
@@ -124,6 +125,26 @@ func (d *PodNetbirdInjector) Default(ctx context.Context, pod *corev1.Pod) error
|
|||||||
Name: "NB_MANAGEMENT_URL",
|
Name: "NB_MANAGEMENT_URL",
|
||||||
Value: d.managementURL,
|
Value: d.managementURL,
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
Name: "NB_LOG_FILE",
|
||||||
|
Value: "console",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "NB_DISABLE_PROFILES",
|
||||||
|
Value: "true",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "NB_DISABLE_UPDATE_SETTINGS",
|
||||||
|
Value: "true",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "NB_DAEMON_ADDR",
|
||||||
|
Value: "unix:///var/run/netbird/netbird.sock",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "NB_ENTRYPOINT_SERVICE_TIMEOUT",
|
||||||
|
Value: "0",
|
||||||
|
},
|
||||||
}
|
}
|
||||||
if len(sidecarProfile.Spec.ExtraDNSLabels) > 0 {
|
if len(sidecarProfile.Spec.ExtraDNSLabels) > 0 {
|
||||||
envVars = append(envVars, corev1.EnvVar{
|
envVars = append(envVars, corev1.EnvVar{
|
||||||
@@ -137,8 +158,44 @@ func (d *PodNetbirdInjector) Default(ctx context.Context, pod *corev1.Pod) error
|
|||||||
Image: d.clientImage,
|
Image: d.clientImage,
|
||||||
Env: envVars,
|
Env: envVars,
|
||||||
SecurityContext: &corev1.SecurityContext{
|
SecurityContext: &corev1.SecurityContext{
|
||||||
|
ReadOnlyRootFilesystem: new(true),
|
||||||
Capabilities: &corev1.Capabilities{
|
Capabilities: &corev1.Capabilities{
|
||||||
Add: []corev1.Capability{"NET_ADMIN"},
|
Add: []corev1.Capability{
|
||||||
|
"NET_ADMIN",
|
||||||
|
"SYS_RESOURCE",
|
||||||
|
"SYS_ADMIN",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
Privileged: new(true),
|
||||||
|
},
|
||||||
|
VolumeMounts: []corev1.VolumeMount{
|
||||||
|
{
|
||||||
|
Name: "netbird-run",
|
||||||
|
MountPath: "/var/run/netbird",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "netbird-lib",
|
||||||
|
MountPath: "/var/lib/netbird",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "ssh-etc",
|
||||||
|
MountPath: "/etc/ssh",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "resolv-conf",
|
||||||
|
MountPath: "/etc/resolv.conf",
|
||||||
|
SubPath: "resolv.conf",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "resolv-conf",
|
||||||
|
MountPath: "/etc/resolv.conf.original.netbird",
|
||||||
|
SubPath: "resolv.conf.original.netbird",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
Resources: corev1.ResourceRequirements{
|
||||||
|
Requests: corev1.ResourceList{
|
||||||
|
corev1.ResourceCPU: resource.MustParse("100m"),
|
||||||
|
corev1.ResourceMemory: resource.MustParse("128Mi"),
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
@@ -161,6 +218,53 @@ func (d *PodNetbirdInjector) Default(ctx context.Context, pod *corev1.Pod) error
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
volumes := []corev1.Volume{
|
||||||
|
{
|
||||||
|
Name: "netbird-run",
|
||||||
|
VolumeSource: corev1.VolumeSource{
|
||||||
|
EmptyDir: &corev1.EmptyDirVolumeSource{},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "netbird-lib",
|
||||||
|
VolumeSource: corev1.VolumeSource{
|
||||||
|
EmptyDir: &corev1.EmptyDirVolumeSource{},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "ssh-etc",
|
||||||
|
VolumeSource: corev1.VolumeSource{
|
||||||
|
EmptyDir: &corev1.EmptyDirVolumeSource{},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
Name: "resolv-conf",
|
||||||
|
VolumeSource: corev1.VolumeSource{
|
||||||
|
EmptyDir: &corev1.EmptyDirVolumeSource{},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
pod.Spec.Volumes = append(pod.Spec.Volumes, volumes...)
|
||||||
|
|
||||||
|
resolvInitContainer := corev1.Container{
|
||||||
|
Name: "resolv-conf",
|
||||||
|
Image: d.clientImage,
|
||||||
|
Command: []string{"sh", "-c", "cp /etc/resolv.conf /tmp/resolv.conf && cp /etc/resolv.conf /tmp/resolv.conf.original.netbird"},
|
||||||
|
SecurityContext: &corev1.SecurityContext{
|
||||||
|
ReadOnlyRootFilesystem: new(true),
|
||||||
|
Capabilities: &corev1.Capabilities{
|
||||||
|
Drop: []corev1.Capability{"ALL"},
|
||||||
|
},
|
||||||
|
},
|
||||||
|
VolumeMounts: []corev1.VolumeMount{
|
||||||
|
{
|
||||||
|
Name: "resolv-conf",
|
||||||
|
MountPath: "/tmp",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
}
|
||||||
|
pod.Spec.InitContainers = append(pod.Spec.InitContainers, resolvInitContainer)
|
||||||
|
|
||||||
switch sidecarProfile.Spec.InjectionMode {
|
switch sidecarProfile.Spec.InjectionMode {
|
||||||
case nbv1alpha1.InjectionModeSidecar:
|
case nbv1alpha1.InjectionModeSidecar:
|
||||||
restartPolicy := corev1.ContainerRestartPolicyAlways
|
restartPolicy := corev1.ContainerRestartPolicyAlways
|
||||||
|
|||||||
Reference in New Issue
Block a user