Add note about deprecated seccomp annotation

We now add a note to clarify that the annotations are deprecated and
will become non-functional in v1.25.

Signed-off-by: Sascha Grunert <sgrunert@redhat.com>
This commit is contained in:
Sascha Grunert
2021-08-17 09:51:11 +02:00
parent 703f8b92f5
commit 5f192f2cb1
2 changed files with 19 additions and 5 deletions
@@ -426,3 +426,9 @@ or updating objects that contain Pod templates, such as Deployments, Jobs, State
See [Enforcing Pod Security at the Namespace Level](/docs/concepts/security/pod-security-admission) See [Enforcing Pod Security at the Namespace Level](/docs/concepts/security/pod-security-admission)
for more information. for more information.
## seccomp.security.alpha.kubernetes.io/pod and container.seccomp.security.alpha.kubernetes.io/[NAME] (deprecated)
The seccomp annotations have been deprecated since Kubernetes v1.19 and will
become non-functional in v1.25. Please use the `seccompProfile` of the
`SecurityContext` instead.
+12 -4
View File
@@ -170,12 +170,20 @@ Download the correct manifest for your Kubernetes version:
{{< tab name="v1.19 or Later (GA)" >}} {{< tab name="v1.19 or Later (GA)" >}}
{{< codenew file="pods/security/seccomp/ga/audit-pod.yaml" >}} {{< codenew file="pods/security/seccomp/ga/audit-pod.yaml" >}}
{{< /tab >}}} {{< /tab >}}}
{{{< tab name="Pre-v1.19 (alpha)" >}} {{{< tab name="Pre-v1.19 (deprecated)" >}}
{{< codenew file="pods/security/seccomp/alpha/audit-pod.yaml" >}} {{< codenew file="pods/security/seccomp/alpha/audit-pod.yaml" >}}
{{< /tab >}} {{< /tab >}}
{{< /tabs >}} {{< /tabs >}}
<br> <br>
{{< note >}}
The functional support for the already deprecated seccomp annotations
`seccomp.security.alpha.kubernetes.io/pod` (for the whole pod) and
`container.seccomp.security.alpha.kubernetes.io/[name]` (for a single container)
is going to be removed with the release of Kubernetes v1.25. Please always use
the native API fields in favor of the annotations.
{{< /note >}}
Create the Pod in the cluster: Create the Pod in the cluster:
``` ```
@@ -270,7 +278,7 @@ Download the correct manifest for your Kubernetes version:
{{< tab name="v1.19 or Later (GA)" >}} {{< tab name="v1.19 or Later (GA)" >}}
{{< codenew file="pods/security/seccomp/ga/violation-pod.yaml" >}} {{< codenew file="pods/security/seccomp/ga/violation-pod.yaml" >}}
{{< /tab >}}} {{< /tab >}}}
{{{< tab name="Pre-v1.19 (alpha)" >}} {{{< tab name="Pre-v1.19 (deprecated)" >}}
{{< codenew file="pods/security/seccomp/alpha/violation-pod.yaml" >}} {{< codenew file="pods/security/seccomp/alpha/violation-pod.yaml" >}}
{{< /tab >}} {{< /tab >}}
{{< /tabs >}} {{< /tabs >}}
@@ -321,7 +329,7 @@ Download the correct manifest for your Kubernetes version:
{{< tab name="v1.19 or Later (GA)" >}} {{< tab name="v1.19 or Later (GA)" >}}
{{< codenew file="pods/security/seccomp/ga/fine-pod.yaml" >}} {{< codenew file="pods/security/seccomp/ga/fine-pod.yaml" >}}
{{< /tab >}}} {{< /tab >}}}
{{{< tab name="Pre-v1.19 (alpha)" >}} {{{< tab name="Pre-v1.19 (deprecated)" >}}
{{< codenew file="pods/security/seccomp/alpha/fine-pod.yaml" >}} {{< codenew file="pods/security/seccomp/alpha/fine-pod.yaml" >}}
{{< /tab >}} {{< /tab >}}
{{< /tabs >}} {{< /tabs >}}
@@ -403,7 +411,7 @@ Download the correct manifest for your Kubernetes version:
{{< tab name="v1.19 or Later (GA)" >}} {{< tab name="v1.19 or Later (GA)" >}}
{{< codenew file="pods/security/seccomp/ga/default-pod.yaml" >}} {{< codenew file="pods/security/seccomp/ga/default-pod.yaml" >}}
{{< /tab >}}} {{< /tab >}}}
{{{< tab name="Pre-v1.19 (alpha)" >}} {{{< tab name="Pre-v1.19 (deprecated)" >}}
{{< codenew file="pods/security/seccomp/alpha/default-pod.yaml" >}} {{< codenew file="pods/security/seccomp/alpha/default-pod.yaml" >}}
{{< /tab >}} {{< /tab >}}
{{< /tabs >}} {{< /tabs >}}