GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy-operator

k8s 1.34 baseline PodSecurity cannot use host field in lifecycle handlers

Offen
#739 2 Kommentare 1 Reaktion 1 zugewiesene Person Beansprucht von @hessjcg Auf GitHub ansehen
Vorherrschende Sprache
Go
Sterne
120
Forks
18
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

Running on k8s 1.34, if you set a PodSecurity level of restricted or baseline, the `host` field is not allowed to be set in lifecycle handlers. The operator injects the following:

```yaml
lifecycle:
preStop:
httpGet:
host: localhost # Violates baseline AND restricted PSA
path: /quitquitquit
port: 9091
```

There is no way to override this without overriding the entire container object, so this ends up leading to the operator not being able to start the pods up.

https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#bug-or-regression-6

> The baseline and restricted pod security admission levels now block setting the host field on probe and lifecycle handlers (https://github.com/kubernetes/kubernetes/pull/125271, [@tssurya](https://github.com/tssurya)) [SIG Auth, Node and Testing]

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.