bpfman / bpfman/bpfman-operator

What is the recommended way to manage security on ebpf programs when loading in SELinux enables clusters

Open
#326 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
38
Forks
27
PR merge metrics
No merged PRs in 30d

Description

When SELinux is enabled in clusters, for example in OpenShift, what is the recommended way to load eBPF programs?

The eBPF examples (bpfman/examples/) use SELinux profiles. Ingress Node Firewall added labels to the namespace (pod-security.kubernetes.io/enforce=privileged and pod-security.kubernetes.io/warn=privileged).

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing the SELinux profiles in bpfman/examples/ and the issue context about OpenShift and Ingress Node Firewall namespace labels. Determine what loading guidance is needed for SELinux-enabled clusters and document the recommended approach. Done means the recommendation and required security configuration are clear to users.

Written by the indexing model from the issue text.

Assessment

Domain
infrastructure, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.