From b7d5b9c4002be563bc1b14d92625da20e7be1ead Mon Sep 17 00:00:00 2001 From: devops4sure Date: Tue, 29 Sep 2026 12:40:01 -0700 Subject: [PATCH] fix(helm): satisfy Restricted Pod Security Standard for certgen hook --- deploy/helm/openshell/README.md | 2 + deploy/helm/openshell/templates/certgen.yaml | 18 ++++---- deploy/helm/openshell/tests/certgen_test.yaml | 44 +++++++++++++++++++ deploy/helm/openshell/values.yaml | 14 ++++++ 4 files changed, 70 insertions(+), 8 deletions(-) diff --git a/deploy/helm/openshell/README.md b/deploy/helm/openshell/README.md index bfb60ddb80..b129f7852e 100644 --- a/deploy/helm/openshell/README.md +++ b/deploy/helm/openshell/README.md @@ -350,6 +350,8 @@ discovery endpoint or its TLS CA. | openshiftRoute.host | string | `""` | Hostname for the Route. Must match a SAN on the gateway's server cert. | | pkiInitJob.enabled | bool | `true` | Run a pre-install/pre-upgrade Job that creates gateway and client mTLS Secrets. When certManager.enabled=true, cert-manager owns TLS and this same hook runs in JWT-only mode even if pkiInitJob.enabled remains true. | | pkiInitJob.failOnTimeout | bool | `true` | Fail the helm install/upgrade if cert-manager does not issue the certificate within the polling timeout. When true (default), the install fails immediately if the timeout is reached, providing clear feedback that BackendTLSPolicy is non-functional. When false, the hook succeeds with a warning and you can run `helm upgrade` after cert-manager issues the certificate to create the backend CA ConfigMap. If you set this to false and see "TLS error: Secret is not supplied by SDS" when connecting to the gateway, check if the TLS secret exists and run `helm upgrade` to create the ConfigMap. | +| pkiInitJob.podSecurityContext | object | `{"seccompProfile":{"type":"RuntimeDefault"}}` | Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. | +| pkiInitJob.securityContext | object | `{"allowPrivilegeEscalation":false,"capabilities":{"drop":["ALL"]},"runAsNonRoot":true,"runAsUser":1000}` | Container-level securityContext for the certgen hook Jobs. Defaults satisfy the Kubernetes Restricted Pod Security Standard. | | pkiInitJob.serverDnsNames | list | `[]` | Extra DNS SANs to append to the server certificate. | | pkiInitJob.serverIpAddresses | list | `[]` | Extra IP SANs to append to the server certificate. | | pkiInitJob.timeoutSeconds | int | `120` | Maximum time in seconds for the certgen hook to poll for cert-manager certificates. When using cert-manager with BackendTLSPolicy, the hook polls for this many seconds waiting for the certificate to be issued, then creates the backend CA ConfigMap. The Job deadline is set to (timeoutSeconds + 30) to allow time for ConfigMap creation and cleanup. Increase this if cert-manager takes longer than 120 seconds to issue certificates. | diff --git a/deploy/helm/openshell/templates/certgen.yaml b/deploy/helm/openshell/templates/certgen.yaml index f7c9a751d3..aeb7417ab6 100644 --- a/deploy/helm/openshell/templates/certgen.yaml +++ b/deploy/helm/openshell/templates/certgen.yaml @@ -83,15 +83,16 @@ spec: imagePullSecrets: {{- toYaml . | nindent 8 }} {{- end }} + {{- with .Values.pkiInitJob.podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} containers: - name: certgen image: {{ include "openshell.image" . | quote }} imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }} securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL + {{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }} env: - name: POD_NAMESPACE valueFrom: @@ -154,15 +155,16 @@ spec: imagePullSecrets: {{- toYaml . | nindent 8 }} {{- end }} + {{- with .Values.pkiInitJob.podSecurityContext }} + securityContext: + {{- toYaml . | nindent 8 }} + {{- end }} containers: - name: certgen image: {{ include "openshell.image" . | quote }} imagePullPolicy: {{ .Values.gateway.image.pullPolicy | default .Values.global.image.pullPolicy }} securityContext: - allowPrivilegeEscalation: false - capabilities: - drop: - - ALL + {{- toYaml .Values.pkiInitJob.securityContext | nindent 12 }} env: - name: POD_NAMESPACE valueFrom: diff --git a/deploy/helm/openshell/tests/certgen_test.yaml b/deploy/helm/openshell/tests/certgen_test.yaml index cd88b60e97..a2b2460e54 100644 --- a/deploy/helm/openshell/tests/certgen_test.yaml +++ b/deploy/helm/openshell/tests/certgen_test.yaml @@ -74,6 +74,50 @@ tests: content: "--jwt-secret-name=custom-jwt-keys" documentIndex: 3 + - it: satisfies the Restricted Pod Security Standard by default + template: templates/certgen.yaml + asserts: + - equal: + path: spec.template.spec.securityContext.seccompProfile.type + value: RuntimeDefault + documentIndex: 3 + - equal: + path: spec.template.spec.containers[0].securityContext.runAsNonRoot + value: true + documentIndex: 3 + - equal: + path: spec.template.spec.containers[0].securityContext.allowPrivilegeEscalation + value: false + documentIndex: 3 + - equal: + path: spec.template.spec.containers[0].securityContext.capabilities.drop + value: ["ALL"] + documentIndex: 3 + + - it: allows overriding the certgen hook security context + template: templates/certgen.yaml + set: + pkiInitJob.podSecurityContext: + seccompProfile: + type: Localhost + localhostProfile: profiles/certgen.json + pkiInitJob.securityContext: + runAsNonRoot: true + runAsUser: 2000 + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL + asserts: + - equal: + path: spec.template.spec.securityContext.seccompProfile.type + value: Localhost + documentIndex: 3 + - equal: + path: spec.template.spec.containers[0].securityContext.runAsUser + value: 2000 + documentIndex: 3 + - it: renders JWT-only hook when cert-manager is enabled even if pkiInitJob remains enabled template: templates/certgen.yaml set: diff --git a/deploy/helm/openshell/values.yaml b/deploy/helm/openshell/values.yaml index 4e7e11142d..80dd2f276e 100644 --- a/deploy/helm/openshell/values.yaml +++ b/deploy/helm/openshell/values.yaml @@ -552,6 +552,20 @@ pkiInitJob: # see "TLS error: Secret is not supplied by SDS" when connecting to the gateway, # check if the TLS secret exists and run `helm upgrade` to create the ConfigMap. failOnTimeout: true + # -- Pod-level securityContext for the certgen hook Jobs. Defaults satisfy the + # Kubernetes Restricted Pod Security Standard. + podSecurityContext: + seccompProfile: + type: RuntimeDefault + # -- Container-level securityContext for the certgen hook Jobs. Defaults + # satisfy the Kubernetes Restricted Pod Security Standard. + securityContext: + runAsNonRoot: true + runAsUser: 1000 + allowPrivilegeEscalation: false + capabilities: + drop: + - ALL # cert-manager Certificate/Issuer resources (requires cert-manager CRDs in-cluster). # Does not install cert-manager itself.