Add documentation for generally available seccomp functionality
Signed-off-by: hasheddan <georgedanielmangum@gmail.com>
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: audit-pod
|
||||
labels:
|
||||
app: audit-pod
|
||||
annotations:
|
||||
seccomp.security.alpha.kubernetes.io/pod: localhost/profiles/audit.json
|
||||
spec:
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: default-pod
|
||||
labels:
|
||||
app: default-pod
|
||||
annotations:
|
||||
seccomp.security.alpha.kubernetes.io/pod: runtime/default
|
||||
spec:
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: fine-pod
|
||||
labels:
|
||||
app: fine-pod
|
||||
annotations:
|
||||
seccomp.security.alpha.kubernetes.io/pod: localhost/profiles/fine-grained.json
|
||||
spec:
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,16 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: violation-pod
|
||||
labels:
|
||||
app: violation-pod
|
||||
annotations:
|
||||
seccomp.security.alpha.kubernetes.io/pod: localhost/profiles/violation.json
|
||||
spec:
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: audit-pod
|
||||
labels:
|
||||
app: audit-pod
|
||||
spec:
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: Localhost
|
||||
localhostProfile: profiles/audit.json
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,17 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: audit-pod
|
||||
labels:
|
||||
app: audit-pod
|
||||
spec:
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: RuntimeDefault
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: fine-pod
|
||||
labels:
|
||||
app: fine-pod
|
||||
spec:
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: Localhost
|
||||
localhostProfile: profiles/fine-grained.json
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,18 @@
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: violation-pod
|
||||
labels:
|
||||
app: violation-pod
|
||||
spec:
|
||||
securityContext:
|
||||
seccompProfile:
|
||||
type: Localhost
|
||||
localhostProfile: profiles/violation.json
|
||||
containers:
|
||||
- name: test-container
|
||||
image: hashicorp/http-echo:0.2.3
|
||||
args:
|
||||
- "-text=just made some syscalls!"
|
||||
securityContext:
|
||||
allowPrivilegeEscalation: false
|
||||
@@ -0,0 +1,7 @@
|
||||
apiVersion: kind.x-k8s.io/v1alpha4
|
||||
kind: Cluster
|
||||
nodes:
|
||||
- role: control-plane
|
||||
extraMounts:
|
||||
- hostPath: "./profiles"
|
||||
containerPath: "/var/lib/kubelet/seccomp/profiles"
|
||||
@@ -0,0 +1,3 @@
|
||||
{
|
||||
"defaultAction": "SCMP_ACT_LOG"
|
||||
}
|
||||
@@ -0,0 +1,65 @@
|
||||
{
|
||||
"defaultAction": "SCMP_ACT_ERRNO",
|
||||
"architectures": [
|
||||
"SCMP_ARCH_X86_64",
|
||||
"SCMP_ARCH_X86",
|
||||
"SCMP_ARCH_X32"
|
||||
],
|
||||
"syscalls": [
|
||||
{
|
||||
"names": [
|
||||
"accept4",
|
||||
"epoll_wait",
|
||||
"pselect6",
|
||||
"futex",
|
||||
"madvise",
|
||||
"epoll_ctl",
|
||||
"getsockname",
|
||||
"setsockopt",
|
||||
"vfork",
|
||||
"mmap",
|
||||
"read",
|
||||
"write",
|
||||
"close",
|
||||
"arch_prctl",
|
||||
"sched_getaffinity",
|
||||
"munmap",
|
||||
"brk",
|
||||
"rt_sigaction",
|
||||
"rt_sigprocmask",
|
||||
"sigaltstack",
|
||||
"gettid",
|
||||
"clone",
|
||||
"bind",
|
||||
"socket",
|
||||
"openat",
|
||||
"readlinkat",
|
||||
"exit_group",
|
||||
"epoll_create1",
|
||||
"listen",
|
||||
"rt_sigreturn",
|
||||
"sched_yield",
|
||||
"clock_gettime",
|
||||
"connect",
|
||||
"dup2",
|
||||
"epoll_pwait",
|
||||
"execve",
|
||||
"exit",
|
||||
"fcntl",
|
||||
"getpid",
|
||||
"getuid",
|
||||
"ioctl",
|
||||
"mprotect",
|
||||
"nanosleep",
|
||||
"open",
|
||||
"poll",
|
||||
"recvfrom",
|
||||
"sendto",
|
||||
"set_tid_address",
|
||||
"setitimer",
|
||||
"writev"
|
||||
],
|
||||
"action": "SCMP_ACT_ALLOW"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,3 @@
|
||||
{
|
||||
"defaultAction": "SCMP_ACT_ERRNO"
|
||||
}
|
||||
Reference in New Issue
Block a user