-
Notifications
You must be signed in to change notification settings - Fork 16
RELEASE 1.5][BACKPORT] Run queue proxy with restricted profile #1283
RELEASE 1.5][BACKPORT] Run queue proxy with restricted profile #1283
Conversation
skonto
commented
Oct 19, 2022
- Backport of knative@388128b
* allow user workloads to run with restricted profile * only change queue proxy
|
/retest |
|
/retest |
|
/assign @nak3 |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: nak3, skonto The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
Btw it seems that OCP adds some capabilities already by default as testing with: Gives the following for the queue-proxy container: This was tested on 4.12.0-ec.4 in a new namespace where we enforce Full pods description here. |
|
Ready to merge. |
|
/retest |
|
/test 410-e2e-aws-ocp-410 |
|
@skonto: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here. |
…hift#1283) * Run queue proxy with restricted profile (knative#13376) * allow user workloads to run with restricted profile * only change queue proxy * remove seccomp
…hift#1283) (openshift#19) * Run queue proxy with restricted profile (knative#13376) * allow user workloads to run with restricted profile * only change queue proxy * remove seccomp Co-authored-by: Stavros Kontopoulos <skontopo@redhat.com>
…hift#1283) (openshift#13) * Run queue proxy with restricted profile (knative#13376) * allow user workloads to run with restricted profile * only change queue proxy * remove seccomp