Skip to content

SLK-93353: Remove CAP_SYS_MODULE from enforcer and kube-enforcer#1041

Open
andreazorzetto wants to merge 1 commit into
aquasecurity:2022.4from
andreazorzetto:az_SLK-93353_remove_sys_module
Open

SLK-93353: Remove CAP_SYS_MODULE from enforcer and kube-enforcer#1041
andreazorzetto wants to merge 1 commit into
aquasecurity:2022.4from
andreazorzetto:az_SLK-93353_remove_sys_module

Conversation

@andreazorzetto
Copy link
Copy Markdown
Collaborator

Summary

Remove CAP_SYS_MODULE from enforcer and kube-enforcer Helm charts. The enforcer does not load kernel modules. Talos Linux blocks this capability, preventing the enforcer container from starting.

Files changed:

  • enforcer/values.yaml
  • enforcer/templates/rbac.yaml
  • aqua-quickstart/templates/rbac.yaml
  • kube-enforcer/values.yaml

Related

The enforcer does not load kernel modules. Talos Linux blocks this
capability, preventing the enforcer container from starting.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant