diff --git a/CHANGELOG.md b/CHANGELOG.md index 67694c9..efa4d14 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,7 @@ All notable changes to this project will be documented in this file. ### Changed - Bump stackable-operator to 0.116.0 ([#439], [#443], [#444]). +- The operator Deployment runs with a restricted security context, so it can be deployed into namespaces that enforce the `restricted` Pod Security Standard ([#462]). ### Fixed @@ -17,6 +18,7 @@ All notable changes to this project will be documented in this file. [#439]: https://github.com/stackabletech/commons-operator/pull/439 [#443]: https://github.com/stackabletech/commons-operator/pull/443 [#444]: https://github.com/stackabletech/commons-operator/pull/444 +[#462]: https://github.com/stackabletech/commons-operator/pull/462 ## [26.7.0] - 2026-07-21 diff --git a/deploy/helm/commons-operator/values.schema.json b/deploy/helm/commons-operator/values.schema.json index d0fae2f..debf23f 100644 --- a/deploy/helm/commons-operator/values.schema.json +++ b/deploy/helm/commons-operator/values.schema.json @@ -110,13 +110,25 @@ "title": "Pod security context", "description": "Pod-level security context for the operator pod, for example fsGroup. Passed through to Kubernetes unchanged. Applies to the operator pod only.", "type": "object", - "default": {} + "default": { + "runAsNonRoot": true, + "seccompProfile": { + "type": "RuntimeDefault" + } + } }, "securityContext": { "title": "Container security context", "description": "Container-level security context for the operator container, for example readOnlyRootFilesystem or runAsNonRoot. Passed through to Kubernetes unchanged. Applies to the operator container only.", "type": "object", - "default": {} + "default": { + "allowPrivilegeEscalation": false, + "capabilities": { + "drop": [ + "ALL" + ] + } + } }, "resources": { "title": "Resource requests and limits", diff --git a/deploy/helm/commons-operator/values.yaml b/deploy/helm/commons-operator/values.yaml index fa1b7cd..5453fac 100644 --- a/deploy/helm/commons-operator/values.yaml +++ b/deploy/helm/commons-operator/values.yaml @@ -32,16 +32,18 @@ podAnnotations: {} labels: stackable.tech/vendor: Stackable -podSecurityContext: {} - # fsGroup: 2000 - -securityContext: {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 +# Satisfies the restricted Pod Security Standard. +# Already standard on OpenShift. +podSecurityContext: + runAsNonRoot: true + seccompProfile: + type: RuntimeDefault + +securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL resources: limits: