GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy-operator

k8s 1.34 baseline PodSecurity cannot use host field in lifecycle handlers

Abierto
#739 2 comentarios 1 reacción 1 asignado Reclamado por @hessjcg Ver en GitHub
Lenguaje dominante
Go
Estrellas
120
Forks
18
Métricas de merge de PR
Sin PR fusionados en 30 d

Descripción

Running on k8s 1.34, if you set a PodSecurity level of restricted or baseline, the `host` field is not allowed to be set in lifecycle handlers. The operator injects the following:

```yaml
lifecycle:
preStop:
httpGet:
host: localhost # Violates baseline AND restricted PSA
path: /quitquitquit
port: 9091
```

There is no way to override this without overriding the entire container object, so this ends up leading to the operator not being able to start the pods up.

https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#bug-or-regression-6

> The baseline and restricted pod security admission levels now block setting the host field on probe and lifecycle handlers (https://github.com/kubernetes/kubernetes/pull/125271, [@tssurya](https://github.com/tssurya)) [SIG Auth, Node and Testing]

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.