I have a critical warning in my local playground cluster that reads like the following:
Sharing the host PID namespace lets the container see and signal all host processes, enabling process injection attacks.
K8s: Pod Security Standards
NSA/CISA Kubernetes Hardening Guide
DAEMONSET
rook-ceph / rook-ceph.rbd.csi.ceph.com-nodeplugin
Rook-Ceph version (Operator and Cluster): 1.19.7
For reference: I first opened it up here: rook/rook#18032 (comment)
I have a critical warning in my local playground cluster that reads like the following:
Sharing the host PID namespace lets the container see and signal all host processes, enabling process injection attacks.
K8s: Pod Security Standards
NSA/CISA Kubernetes Hardening Guide
DAEMONSET
rook-ceph / rook-ceph.rbd.csi.ceph.com-nodeplugin
Rook-Ceph version (Operator and Cluster): 1.19.7
For reference: I first opened it up here: rook/rook#18032 (comment)