Skip to content

Commit b7d5b9c

Browse files
committed
fix(helm): satisfy Restricted Pod Security Standard for certgen hook
1 parent c0eb3db commit b7d5b9c

4 files changed

Lines changed: 70 additions & 8 deletions

File tree

‎deploy/helm/openshell/README.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -350,6 +350,8 @@ discovery endpoint or its TLS CA.
350350
| openshiftRoute.host | string | `""` | Hostname for the Route. Must match a SAN on the gateway's server cert. |
351351
| pkiInitJob.enabled | bool | `true` | Run a pre-install/pre-upgrade Job that creates gateway and client mTLS Secrets. When certManager.enabled=true, cert-manager owns TLS and this same hook runs in JWT-only mode even if pkiInitJob.enabled remains true. |
352352
| pkiInitJob.failOnTimeout | bool | `true` | Fail the helm install/upgrade if cert-manager does not issue the certificate within the polling timeout. When true (default), the install fails immediately if the timeout is reached, providing clear feedback that BackendTLSPolicy is non-functional. When false, the hook succeeds with a warning and you can run `helm upgrade` after cert-manager issues the certificate to create the backend CA ConfigMap. If you set this to false and see "TLS error: Secret is not supplied by SDS" when connecting to the gateway, check if the TLS secret exists and run `helm upgrade` to create the ConfigMap. |
353+
| pkiInitJob.podSecurityContext | object | `{"seccompProfile":{"type":"RuntimeDefault"}}` | Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. |
354+
| pkiInitJob.securityContext | object | `{"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"runAsNonRoot":true,"runAsUser":1000}` | Container-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. |
353355
| pkiInitJob.serverDnsNames | list | `[]` | Extra DNS SANs to append to the server certificate. |
354356
| pkiInitJob.serverIpAddresses | list | `[]` | Extra IP SANs to append to the server certificate. |
355357
| pkiInitJob.timeoutSeconds | int | `120` | Maximum time in seconds for the certgen hook to poll for cert-manager certificates. When using cert-manager with BackendTLSPolicy, the hook polls for this many seconds waiting for the certificate to be issued, then creates the backend CA ConfigMap. The Job deadline is set to (timeoutSeconds + 30) to allow time for ConfigMap creation and cleanup. Increase this if cert-manager takes longer than 120 seconds to issue certificates. |

‎deploy/helm/openshell/templates/certgen.yaml‎

Lines changed: 10 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -83,15 +83,16 @@ spec:
8383
imagePullSecrets:
8484
{{- toYaml . | nindent 8 }}
8585
{{- end }}
86+
{{- with .Values.pkiInitJob.podSecurityContext }}
87+
securityContext:
88+
{{- toYaml . | nindent 8 }}
89+
{{- end }}
8690
containers:
8791
- name: certgen
8892
image: {{ include "openshell.image" . | quote }}
8993
imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }}
9094
securityContext:
91-
allowPrivilegeEscalation: false
92-
capabilities:
93-
drop:
94-
- ALL
95+
{{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }}
9596
env:
9697
- name: POD_NAMESPACE
9798
valueFrom:
@@ -154,15 +155,16 @@ spec:
154155
imagePullSecrets:
155156
{{- toYaml . | nindent 8 }}
156157
{{- end }}
158+
{{- with .Values.pkiInitJob.podSecurityContext }}
159+
securityContext:
160+
{{- toYaml . | nindent 8 }}
161+
{{- end }}
157162
containers:
158163
- name: certgen
159164
image: {{ include "openshell.image" . | quote }}
160165
imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }}
161166
securityContext:
162-
allowPrivilegeEscalation: false
163-
capabilities:
164-
drop:
165-
- ALL
167+
{{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }}
166168
env:
167169
- name: POD_NAMESPACE
168170
valueFrom:

‎deploy/helm/openshell/tests/certgen_test.yaml‎

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -74,6 +74,50 @@ tests:
7474
content: "--jwt-secret-name=custom-jwt-keys"
7575
documentIndex: 3
7676

77+
- it: satisfies the Restricted Pod Security Standard by default
78+
template: templates/certgen.yaml
79+
asserts:
80+
- equal:
81+
path: spec.template.spec.securityContext.seccompProfile.type
82+
value: RuntimeDefault
83+
documentIndex: 3
84+
- equal:
85+
path: spec.template.spec.containers[0].securityContext.runAsNonRoot
86+
value: true
87+
documentIndex: 3
88+
- equal:
89+
path: spec.template.spec.containers[0].securityContext.allowPrivilegeEscalation
90+
value: false
91+
documentIndex: 3
92+
- equal:
93+
path: spec.template.spec.containers[0].securityContext.capabilities.drop
94+
value: ["ALL"]
95+
documentIndex: 3
96+
97+
- it: allows overriding the certgen hook security context
98+
template: templates/certgen.yaml
99+
set:
100+
pkiInitJob.podSecurityContext:
101+
seccompProfile:
102+
type: Localhost
103+
localhostProfile: profiles/certgen.json
104+
pkiInitJob.securityContext:
105+
runAsNonRoot: true
106+
runAsUser: 2000
107+
allowPrivilegeEscalation: false
108+
capabilities:
109+
drop:
110+
- ALL
111+
asserts:
112+
- equal:
113+
path: spec.template.spec.securityContext.seccompProfile.type
114+
value: Localhost
115+
documentIndex: 3
116+
- equal:
117+
path: spec.template.spec.containers[0].securityContext.runAsUser
118+
value: 2000
119+
documentIndex: 3
120+
77121
- it: renders JWT-only hook when cert-manager is enabled even if pkiInitJob remains enabled
78122
template: templates/certgen.yaml
79123
set:

‎deploy/helm/openshell/values.yaml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -552,6 +552,20 @@ pkiInitJob:
552552
# see "TLS error: Secret is not supplied by SDS" when connecting to the gateway,
553553
# check if the TLS secret exists and run `helm upgrade` to create the ConfigMap.
554554
failOnTimeout: true
555+
# -- Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the
556+
# Kubernetes Restricted Pod Security Standard.
557+
podSecurityContext:
558+
seccompProfile:
559+
type: RuntimeDefault
560+
# -- Container-level securityContext for the certgen hook Jobs. Defaults
561+
# satisfy the Kubernetes Restricted Pod Security Standard.
562+
securityContext:
563+
runAsNonRoot: true
564+
runAsUser: 1000
565+
allowPrivilegeEscalation: false
566+
capabilities:
567+
drop:
568+
- ALL
555569

556570
# cert-manager Certificate/Issuer resources (requires cert-manager CRDs in-cluster).
557571
# Does not install cert-manager itself.

0 commit comments

Comments
 (0)