Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@saschagrunert
Copy link
Member

@saschagrunert saschagrunert commented Nov 9, 2020

What type of PR is this?

/kind feature

What this PR does / why we need it:

We now add support for seccomp security profiles within the CRI. We still support the deprecated code paths until the field is not available any more.

AppArmor support will follow later on.

Which issue(s) this PR fixes:

None

Special notes for your reviewer:

None

Does this PR introduce a user-facing change?

Support Container Runtime Interface (CRI) security profiles for seccomp, which has been introduced with Kubernetes v1.20.0 and the graduation of the CRI.

@openshift-ci-robot openshift-ci-robot added release-note Denotes a PR that will be considered when it comes time to generate release notes. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/feature Categorizes issue or PR as related to a new feature. labels Nov 9, 2020
@openshift-ci-robot openshift-ci-robot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Nov 9, 2020
@codecov
Copy link

codecov bot commented Nov 9, 2020

Codecov Report

Merging #4358 (04240b5) into master (4485573) will increase coverage by 0.18%.
The diff coverage is 41.75%.

@@            Coverage Diff             @@
##           master    #4358      +/-   ##
==========================================
+ Coverage   40.45%   40.64%   +0.18%     
==========================================
  Files         110      110              
  Lines        9443     9493      +50     
==========================================
+ Hits         3820     3858      +38     
- Misses       5191     5193       +2     
- Partials      432      442      +10     

@saschagrunert saschagrunert force-pushed the cri-security-profile branch 2 times, most recently from ca999f2 to 770a10b Compare November 9, 2020 11:39
@saschagrunert
Copy link
Member Author

/retest

1 similar comment
@saschagrunert
Copy link
Member Author

/retest

@TomSweeneyRedHat
Copy link
Contributor

LGTM
assuming happy tests

@saschagrunert
Copy link
Member Author

/retest

@mrunalp
Copy link
Member

mrunalp commented Nov 11, 2020

/lgtm

@openshift-ci-robot
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: mrunalp, saschagrunert

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:
  • OWNERS [mrunalp,saschagrunert]

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Nov 11, 2020
@mrunalp
Copy link
Member

mrunalp commented Nov 11, 2020

/retest

@mrunalp
Copy link
Member

mrunalp commented Nov 12, 2020

/test e2e-aws

@saschagrunert
Copy link
Member Author

/retest

1 similar comment
@umohnani8
Copy link
Member

/retest

@umohnani8
Copy link
Member

umohnani8 commented Nov 13, 2020

Looks like bootstrap failed due to service quota, will hit retest in a bit again.

@saschagrunert
Copy link
Member Author

/retest

@saschagrunert
Copy link
Member Author

/test integration_cgroupv2

@haircommander
Copy link
Member

/retest

2 similar comments
@saschagrunert
Copy link
Member Author

/retest

@haircommander
Copy link
Member

/retest

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

8 similar comments
@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

@openshift-bot
Copy link

/retest

Please review the full test history for this PR and help us cut down flakes.

We now add support for seccomp profiles within the CRI. We still support
the deprecated code paths until the field is not available any more.

AppArmor support will follow later on.

Signed-off-by: Sascha Grunert <[email protected]>
@saschagrunert saschagrunert force-pushed the cri-security-profile branch from a4b4d6f to af4786b Compare March 5, 2021 08:22
@openshift-ci-robot openshift-ci-robot removed the lgtm Indicates that a PR is ready to be merged. label Mar 5, 2021
@saschagrunert
Copy link
Member Author

Had to give this one a rebase.

@saschagrunert
Copy link
Member Author

/test critest_fedora

@haircommander
Copy link
Member

/lgtm

@openshift-ci-robot openshift-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Mar 5, 2021
@haircommander
Copy link
Member

/override ci/kata-jenkins

@openshift-ci-robot
Copy link

@haircommander: Overrode contexts on behalf of haircommander: ci/kata-jenkins

Details

In response to this:

/override ci/kata-jenkins

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci-robot
Copy link

@saschagrunert: The following test failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/kata-jenkins af4786b link /test kata-containers
Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

@haircommander
Copy link
Member

/test integration_crun
/override ci/kata-jenkins

@openshift-ci-robot
Copy link

@haircommander: Overrode contexts on behalf of haircommander: ci/kata-jenkins

Details

In response to this:

/test integration_crun
/override ci/kata-jenkins

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@openshift-ci
Copy link
Contributor

openshift-ci bot commented Mar 5, 2021

@saschagrunert: The following tests failed, say /retest to rerun all failed tests:

Test name Commit Details Rerun command
ci/prow/e2e-gcp af4786b link /test e2e-gcp
ci/prow/e2e-agnostic af4786b link /test e2e-agnostic
ci/openshift-jenkins/integration_crun_cgroupv2 af4786b link /test integration_cgroupv2

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. dco-signoff: yes Indicates the PR's author has DCO signed all their commits. kind/feature Categorizes issue or PR as related to a new feature. lgtm Indicates that a PR is ready to be merged. release-note Denotes a PR that will be considered when it comes time to generate release notes.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants