security(kubescape): set the non-root group fields on coroot-operator - #4218
Conversation
The operator runs as 65534 with all capabilities dropped and no volumes, so stating runAsUser, runAsGroup and fsGroup at pod level changes nothing about how it runs and moves it out of the C-0211 gap set. Eleven genuinely elevated workloads remain. Fixes #4217 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tor group fields The production-authorization job reported exactly one changed entry, HelmRelease observability/coroot-operator, from the runAsUser, runAsGroup and fsGroup values the operator image already runs as. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai review |
|
|
Warning Review limit reachedNext included review available in 25 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository YAML (base), Organization UI (inherited) Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
@coderabbitai review |
@codex review |
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Post-deploy read-back on the live cluster (read-only): the |
Why
A broad security scan exception can only be narrowed once each workload it covers is either fixed or given its own exception with a stated reason. The Coroot operator was listed among the workloads that need elevated privileges, but it does not. It already runs as an unprivileged user and mounts no volumes.
What
The operator now states the user and group it already runs as, so the scan no longer flags it. Eleven workloads remain; each of them does need elevated privileges, and the exception's notes now list exactly those eleven.
Fixes #4217