From 7e14f6b0a7b95f2662e4906a00ccda8dfe5d233a Mon Sep 17 00:00:00 2001 From: Lars Francke Date: Thu, 17 Sep 2026 15:46:44 +0200 Subject: [PATCH 1/2] feat: Set a restricted security context on the operator Deployment --- .../helm/commons-operator/values.schema.json | 16 ++++++++++++-- deploy/helm/commons-operator/values.yaml | 22 ++++++++++--------- 2 files changed, 26 insertions(+), 12 deletions(-) diff --git a/deploy/helm/commons-operator/values.schema.json b/deploy/helm/commons-operator/values.schema.json index d0fae2f..debf23f 100644 --- a/deploy/helm/commons-operator/values.schema.json +++ b/deploy/helm/commons-operator/values.schema.json @@ -110,13 +110,25 @@ "title": "Pod security context", "description": "Pod-level security context for the operator pod, for example fsGroup. Passed through to Kubernetes unchanged. Applies to the operator pod only.", "type": "object", - "default": {} + "default": { + "runAsNonRoot": true, + "seccompProfile": { + "type": "RuntimeDefault" + } + } }, "securityContext": { "title": "Container security context", "description": "Container-level security context for the operator container, for example readOnlyRootFilesystem or runAsNonRoot. Passed through to Kubernetes unchanged. Applies to the operator container only.", "type": "object", - "default": {} + "default": { + "allowPrivilegeEscalation": false, + "capabilities": { + "drop": [ + "ALL" + ] + } + } }, "resources": { "title": "Resource requests and limits", diff --git a/deploy/helm/commons-operator/values.yaml b/deploy/helm/commons-operator/values.yaml index fa1b7cd..5453fac 100644 --- a/deploy/helm/commons-operator/values.yaml +++ b/deploy/helm/commons-operator/values.yaml @@ -32,16 +32,18 @@ podAnnotations: {} labels: stackable.tech/vendor: Stackable -podSecurityContext: {} - # fsGroup: 2000 - -securityContext: {} - # capabilities: - # drop: - # - ALL - # readOnlyRootFilesystem: true - # runAsNonRoot: true - # runAsUser: 1000 +# Satisfies the restricted Pod Security Standard. +# Already standard on OpenShift. +podSecurityContext: + runAsNonRoot: true + seccompProfile: + type: RuntimeDefault + +securityContext: + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL resources: limits: From 46448992679b2c3b28fa3d6aed4b600fd3ca1657 Mon Sep 17 00:00:00 2001 From: Lars Francke Date: Sat, 3 Oct 2026 23:34:35 +0200 Subject: [PATCH 2/2] chore: Add changelog entry --- CHANGELOG.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 67694c9..efa4d14 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,7 @@ All notable changes to this project will be documented in this file. ### Changed - Bump stackable-operator to 0.116.0 ([#439], [#443], [#444]). +- The operator Deployment runs with a restricted security context, so it can be deployed into namespaces that enforce the `restricted` Pod Security Standard ([#462]). ### Fixed @@ -17,6 +18,7 @@ All notable changes to this project will be documented in this file. [#439]: https://github.com/stackabletech/commons-operator/pull/439 [#443]: https://github.com/stackabletech/commons-operator/pull/443 [#444]: https://github.com/stackabletech/commons-operator/pull/444 +[#462]: https://github.com/stackabletech/commons-operator/pull/462 ## [26.7.0] - 2026-07-21