Skip to content

Setup additional hardening for pods#168

Merged
1602077 merged 2 commits into
cvmfs-contrib:masterfrom
jcpunk:harden-pods
Feb 6, 2026
Merged

Setup additional hardening for pods#168
1602077 merged 2 commits into
cvmfs-contrib:masterfrom
jcpunk:harden-pods

Conversation

@jcpunk

@jcpunk jcpunk commented Jan 16, 2026

Copy link
Copy Markdown
Contributor

This PR adds a number of security hardening best practices to the cvmfs plugins.

hostUsers seems to require the ability to chown the filesystem, which is a non-starter.

The acutal mount bits all require system privileges, so they can't be locked down much further.

jcpunk and others added 2 commits January 16, 2026 13:24
@1602077

1602077 commented Feb 6, 2026

Copy link
Copy Markdown
Collaborator

@jcpunk Thank you for this and the other related PRs over the last few weeks!

Apologies I missed them in my inbox. I will release a rc version today to test and validate that includes these fixes and then tag the official candidate for you early next week.

Cheers,
Jack

@1602077 1602077 merged commit 0a591f7 into cvmfs-contrib:master Feb 6, 2026
2 checks passed
@jcpunk jcpunk deleted the harden-pods branch February 6, 2026 14:03
@jcpunk

jcpunk commented Feb 6, 2026

Copy link
Copy Markdown
Contributor Author

Sounds good, I think I closed out some of the github issues, but they didn't link up?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants