Repository navigation
[metal3] ironic: let dnsmasq use its NET_BIND_SERVICE file-cap (#256) - #257
Conversation
|
Hi @ndreno - thanks a lot for the PR! Apologies but this needs a rebase because #254 from @diconico07 merged - when doing this I'd suggest splitting the PR into two commits:
If you check recently merged PRs you will see a similar pattern - this makes review much easier, and also rebases when needed (you can just drop the "make charts" commit and run make again to generate it) |
…edge#256) The ironic-dnsmasq container runs non-root (runAsUser 10475) but must bind privileged ports (DHCP 67, TFTP 69). The ironic image already grants the needed file-caps: setcap cap_net_bind_service,cap_net_raw,cap_net_admin+eip /usr/sbin/dnsmasq but file-caps are inert while no_new_privs is on, so dnsmasq still fails to bind. Two fixes, both in the ironic subchart: 1. values.yaml: dnsmasqSecurityContext now sets allowPrivilegeEscalation: true (so the file-caps take effect) and adds NET_BIND_SERVICE to the bounding set (required for the +e file-cap to apply). Container stays non-root. 2. deployment.yaml: flip the `merge` argument order for the dnsmasq securityContext. `merge` favours the first dict, so the shared securityContext was overriding the per-container dnsmasqSecurityContext (allowPrivilegeEscalation:false always won). dnsmasqSecurityContext must take precedence. Bumps ironic 0.13.1 -> 0.13.2 and metal3 0.15.1 -> 0.15.2. NOTE: this is inert until the downstream ironic image carries the upstream setcap (already present in metal3-io/ironic-image's configure-nonroot.sh). Refs: suse-edge#256 Signed-off-by: Nicolas Dreno <ndreno@gmail.com>
Signed-off-by: Nicolas Dreno <ndreno@gmail.com>
c2ae87d to
126d74f
Compare
|
hey guys, any update? |
Sorry for the slow follow up on this @ndreno - thanks a lot for the contribution! It LGTM, I guess we still need to resolve this issue in the downstream image before merging?
|
|
Actually I see you fixed that in https://src.opensuse.org/suse-edge/Factory/commit/410d878f5d328dd4c769370573b0a1a7a7de5d9a11a3b6faaf07b8e2e800df8a (thanks!) but it's not yet been released to https://build.opensuse.org/project/show/isv:SUSE:Edge:Containers - I will speak with @diconico07 and we can get that updated so we can proceed with this PR, thanks for your patience! |
|
Thanks, keep me posted please :) |
|
Unfortunately some automation bumped the Ironic RPM to v38 (used in our builds of Ironic image) before I published the updated image, so I'll merge this one but it will remain inert until I update the chart here to use Ironic image v38 (and publish final v38 image). |
What
Implements Option 1 from #256 (the direction @diconico07 favoured): keep the
ironic-dnsmasqcontainer non-root, and make the file-caps it's granted actually effective so it can bind DHCP (67) / TFTP (69).Rebased on top of #254 (Metal3 0.15.1 / Ironic 0.13.1) and split into two commits as @hardys requested:
packages/*make charts && make html(charts/,assets/,index.*)Two functional changes, both in the
ironicsubchart:values.yaml—dnsmasqSecurityContext:allowPrivilegeEscalation: true— withoutno_new_privsoff, the binary's file-caps never take effect, so dnsmasq can't bind privileged ports.NET_BIND_SERVICEto the capability set — it must be in the bounding set for the+efile-cap to apply.runAsUser: 10475/runAsNonRoot: true— smallest possible deviation from the current hardening.templates/deployment.yaml— merge order:mergefavours the first dict, so the sharedsecurityContextwas silently overriding the per-containerdnsmasqSecurityContext(allowPrivilegeEscalation: falsealways won). The per-container context must take precedence.Rendered result (
helm template, dnsmasq container) — non-root preserved:Versions
Bumps
ironic0.13.1 → 0.13.2 andmetal30.15.1 → 0.15.2 (metal3appVersionstays 0.15.1 — this is a chart-only fix, no upstream app change); regeneratedcharts/,assets/,index.yaml,index.htmlviamake charts+make html.Dependency / sequencing
As @diconico07 noted in #256, this is inert until the downstream ironic image carries the
setcap— it's already present upstream inmetal3-io/ironic-imageconfigure-nonroot.sh(setcap "cap_net_raw,cap_net_admin,cap_net_bind_service=+eip" /usr/sbin/dnsmasq) but wasn't propagated into the SLE rebuild. Happy to hold/rebase this until that lands.Verified working on RKE2 + SELinux-enforcing during a Metal3 bare-metal PoC (dnsmasq bound DHCP/TFTP, a real node PXE-booted).
Closes #256