- 
                Notifications
    You must be signed in to change notification settings 
- Fork 181
[release-4.18] OCPBUGS-63119: SCC: add hostmount-anyuid-v2 #1937
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[release-4.18] OCPBUGS-63119: SCC: add hostmount-anyuid-v2 #1937
Conversation
the intent of hostmount-anyuid is to allow a pod access to paths on the host. The problem is, hostPath volumes aren't selinux relabeled, and there are paths that the default selinux type `container_t` cannot access. This breaks expectation, and makes pods that rely on hostmount-anyuid brittle to selinux changes on the host (see https://issues.redhat.com/browse/OCPBUGS-55013) Instead of relaxing permissions of all paths on the host, or increasing the ability of container_t, we should trust pods that are granted access to this already powerful SCC to use its power fully. Signed-off-by: Peter Hunt <pehunt@redhat.com>
| @openshift-cherrypick-robot: Jira Issue OCPBUGS-56266 has been cloned as Jira Issue OCPBUGS-63119. Will retitle bug to link to clone. In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. | 
| Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the  You can disable this status message by setting the  ✨ Finishing touches🧪 Generate unit tests (beta)
 Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment  | 
| @openshift-cherrypick-robot: This pull request references Jira Issue OCPBUGS-63119, which is valid. The bug has been moved to the POST state. 7 validation(s) were run on this bug
 Requesting review from QA contact: The bug has been updated to refer to the pull request using the external bug tracker. In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. | 
| The background is that one of mco pr was backported to 4.18 and 4.17, which caused pods to fail mounting certain hostPaths when using the hostmount-anyuid SCC. Therefore, this PR also needs to be backported to 4.18 and 4.17 | 
| @lwan-wanglin: GitHub didn't allow me to request PR reviews from the following users: to, review. Note that only openshift members and repo collaborators can review this PR, and authors cannot review their own PRs. In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. | 
| /retest | 
| /cc @vrutkovs could you apporve it? | 
| /retest | 
| /approve | 
| [APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: openshift-cherrypick-robot, vrutkovs The full list of commands accepted by this bot can be found here. The pull request process is described here 
Needs approval from an approver in each of these files:
 
 Approvers can indicate their approval by writing  | 
| @Prashanth684 Could you please add the lgtm and any other required labels? Thanks! | 
| /backport-risk-assessed | 
| @openshift-cherrypick-robot: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. | 
| /verified by @lwan-wanglin | 
| @Prashanth684: This PR has been marked as verified by  In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. | 
bac8a7c
      into
      
  
    openshift:release-4.18
  
    | @openshift-cherrypick-robot: Jira Issue Verification Checks: Jira Issue OCPBUGS-63119 Jira Issue OCPBUGS-63119 has been moved to the MODIFIED state and will move to the VERIFIED state when the change is available in an accepted nightly payload. 🕓 In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. | 
| /cherry-pick release-4.17 | 
| @lwan-wanglin: new pull request created: #1954 In response to this: 
 Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. | 
| Fix included in accepted release 4.18.0-0.nightly-2025-10-28-171242 | 
This is an automated cherry-pick of #1844
/assign lwan-wanglin