Skip to content

Commit

Permalink
Add SecurityContext to restore-helper
Browse files Browse the repository at this point in the history
This commit adds SecurityContext that complies with "restricted" level
per Pod Security Standards to "restore-helper" initContainer.
It ensures the restore won't fail when the cluster enforces PSA.

Signed-off-by: Daniel Jiang <daniel.jiang@broadcom.com>
  • Loading branch information
reasonerjt committed Dec 9, 2024
1 parent 3476530 commit aad2647
Show file tree
Hide file tree
Showing 4 changed files with 45 additions and 5 deletions.
1 change: 1 addition & 0 deletions changelogs/unreleased/8491-reasonerjt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add SecurityContext to restore-helper
1 change: 1 addition & 0 deletions changelogs/unreleased/8495-reasonerjt
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add SecurityContext to restore-helper
32 changes: 29 additions & 3 deletions pkg/restore/actions/pod_volume_restore_action.go
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,8 @@ import (
"fmt"
"strings"

"github.com/vmware-tanzu/velero/pkg/util/boolptr"

"github.com/pkg/errors"
"github.com/sirupsen/logrus"
corev1 "k8s.io/api/core/v1"
Expand All @@ -44,6 +46,7 @@ const (
defaultCPURequestLimit = "100m"
defaultMemRequestLimit = "128Mi"
defaultCommand = "/velero-restore-helper"
restoreHelperUID = 1000
)

type PodVolumeRestoreAction struct {
Expand Down Expand Up @@ -143,9 +146,15 @@ func (a *PodVolumeRestoreAction) Execute(input *velero.RestoreItemActionExecuteI

runAsUser, runAsGroup, allowPrivilegeEscalation, secCtx := getSecurityContext(log, config)

securityContext, err := kube.ParseSecurityContext(runAsUser, runAsGroup, allowPrivilegeEscalation, secCtx)
if err != nil {
log.Errorf("Using default securityContext values, couldn't parse securityContext requirements: %s.", err)
var securityContext corev1.SecurityContext
if runAsUser == "" && runAsGroup == "" && allowPrivilegeEscalation == "" && secCtx == "" {
securityContext = defaultSecurityCtx()
} else {
securityContext, err = kube.ParseSecurityContext(runAsUser, runAsGroup, allowPrivilegeEscalation, secCtx)
if err != nil {
log.Errorf("Using default securityContext values, couldn't parse securityContext requirements: %s.", err)
securityContext = defaultSecurityCtx()
}
}

initContainerBuilder := newRestoreInitContainerBuilder(image, string(input.Restore.UID))
Expand Down Expand Up @@ -282,3 +291,20 @@ func newRestoreInitContainerBuilder(image, restoreUID string) *builder.Container
},
}...)
}

// defaultSecurityCtx returns a default security context for the init container, which has the level "restricted" per
// Pod Security Standards.
func defaultSecurityCtx() corev1.SecurityContext {
uid := int64(restoreHelperUID)
return corev1.SecurityContext{
AllowPrivilegeEscalation: boolptr.False(),
Capabilities: &corev1.Capabilities{
Drop: []corev1.Capability{"ALL"},
},
SeccompProfile: &corev1.SeccompProfile{
Type: corev1.SeccompProfileTypeRuntimeDefault,
},
RunAsUser: &uid,
RunAsNonRoot: boolptr.True(),
}
}
16 changes: 14 additions & 2 deletions pkg/restore/actions/pod_volume_restore_action_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ import (
"sort"
"testing"

"github.com/vmware-tanzu/velero/pkg/util/boolptr"

"github.com/sirupsen/logrus"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
Expand Down Expand Up @@ -113,8 +115,18 @@ func TestPodVolumeRestoreActionExecute(t *testing.T) {
defaultCPURequestLimit, defaultMemRequestLimit, // requests
defaultCPURequestLimit, defaultMemRequestLimit, // limits
)

securityContext, _ := kube.ParseSecurityContext("", "", "", "")
id := int64(1000)
securityContext := corev1api.SecurityContext{
AllowPrivilegeEscalation: boolptr.False(),
Capabilities: &corev1api.Capabilities{
Drop: []corev1api.Capability{"ALL"},
},
SeccompProfile: &corev1api.SeccompProfile{
Type: corev1api.SeccompProfileTypeRuntimeDefault,
},
RunAsUser: &id,
RunAsNonRoot: boolptr.True(),
}

var (
restoreName = "my-restore"
Expand Down

0 comments on commit aad2647

Please sign in to comment.