Skip to content

fix/webhook runasnonroot stack - #37

Merged
plan9better merged 3 commits into
masterfrom
fix/webhook-runasnonroot-stack
Sep 3, 2026
Merged

plan9better merged 3 commits into
masterfrom
fix/webhook-runasnonroot-stack

Conversation

@plan9better

Copy link
Copy Markdown
Collaborator
  • fix(webhook): pin injected iface-request container to runAsUser 0
  • fix(init-container): override runAsNonRoot per container
  • fix(monitoring): dont query podmonitor if monitoring is disabled

mz2478318291 and others added 3 commits August 25, 2026 10:58
VXLAN device creation (cmd/vxlandlord) needs root regardless of granted
capabilities - confirmed by reproducing with a minimal netlink.LinkAdd
call under the exact same NET_ADMIN-only security context: succeeds as
uid 0, fails with "operation not permitted" as any non-root uid. This
container gets injected into an arbitrary workload pod, which inherits
that pod's securityContext.runAsUser if it sets one (e.g. most
StatefulSets running as non-root) unless overridden per-container.
@plan9better
plan9better merged commit d688a4e into master Sep 3, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants