Skip to content

security(kubescape): set the non-root group fields on coroot-operator - #4218

Merged
devantler merged 2 commits into
mainfrom
claude/kubescape-coroot-operator-group-4217
Sep 26, 2026
Merged

devantler merged 2 commits into
mainfrom
claude/kubescape-coroot-operator-group-4217

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

A broad security scan exception can only be narrowed once each workload it covers is either fixed or given its own exception with a stated reason. The Coroot operator was listed among the workloads that need elevated privileges, but it does not. It already runs as an unprivileged user and mounts no volumes.

What

The operator now states the user and group it already runs as, so the scan no longer flags it. Eleven workloads remain; each of them does need elevated privileges, and the exception's notes now list exactly those eleven.

Fixes #4217

The operator runs as 65534 with all capabilities dropped and no volumes,
so stating runAsUser, runAsGroup and fsGroup at pod level changes nothing
about how it runs and moves it out of the C-0211 gap set. Eleven
genuinely elevated workloads remain.

Fixes #4217

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tor group fields

The production-authorization job reported exactly one changed entry,
HelmRelease observability/coroot-operator, from the runAsUser, runAsGroup
and fsGroup values the operator image already runs as.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 25 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e6e102ad-4763-4335-93a3-ee109e0e9d07

📥 Commits

Reviewing files that changed from the base of the PR and between dfee0e2 and 4b44fcd.

📒 Files selected for processing (4)
  • k8s/bases/infrastructure/cluster-security-exceptions/pod-security-mutations-unscoped.yaml
  • k8s/bases/infrastructure/controllers/coroot/helm-release.yaml
  • k8s/bases/infrastructure/controllers/kubescape/config-map-headlamp-exceptions.yaml
  • scripts/validate-eks-ci-role-policy/main.go

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai review

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@codex review

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T18:23:37.409602Z 4b44fcd Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 👍

Reviewed commit: 4b44fcdeab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@devantler
devantler marked this pull request as ready for review September 26, 2026 18:27
@devantler
devantler added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit f7b2bc9 Sep 26, 2026
31 checks passed
@devantler
devantler deleted the claude/kubescape-coroot-operator-group-4217 branch September 26, 2026 18:46
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Post-deploy read-back on the live cluster (read-only): the coroot-operator HelmRelease reports Helm upgrade succeeded (release v10), the Deployment is Ready 1/1, and its pod security context now runs as user/group 65534 with fsGroup: 65534, runAsNonRoot: true and the RuntimeDefault seccomp profile. The fix is live.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

security(kubescape): set the non-root group fields on coroot-operator at source

1 participant