bpfman / bpfman/bpfman-operator
What is the recommended way to manage security on ebpf programs when loading in SELinux enables clusters
- Dominant language
- Go
- Stars
- 38
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Description
When SELinux is enabled in clusters, for example in OpenShift, what is the recommended way to load eBPF programs?
The eBPF examples (bpfman/examples/) use SELinux profiles. Ingress Node Firewall added labels to the namespace (pod-security.kubernetes.io/enforce=privileged and pod-security.kubernetes.io/warn=privileged).
Contributor guide
No contributing guide indexed for this repository
Research direction
Start by reviewing the SELinux profiles in bpfman/examples/ and the issue context about OpenShift and Ingress Node Firewall namespace labels. Determine what loading guidance is needed for SELinux-enabled clusters and document the recommended approach. Done means the recommendation and required security configuration are clear to users.
Written by the indexing model from the issue text.
Assessment
- Domain
- infrastructure, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100