You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
on OCP, we need a custom selinux policy to grant RTE(/NFD) access to the podresources socket. Thanks to the latest fixes in the most recent container-selinux package, we can use now a different but very compatible selinux process context (container_device_plugin_t) which is very close to the permissions we need.
In addition, delivering a new custom selinux policy
requires a reboot to worker nodes, which is undesirable
requires cleanup on removal, which we don't, littering the worker nodes
so it's time to switch default and make the custom selinux policy available but opt-in.
The text was updated successfully, but these errors were encountered:
on OCP, we need a custom selinux policy to grant RTE(/NFD) access to the podresources socket. Thanks to the latest fixes in the most recent container-selinux package, we can use now a different but very compatible selinux process context (
container_device_plugin_t
) which is very close to the permissions we need.In addition, delivering a new custom selinux policy
so it's time to switch default and make the custom selinux policy available but opt-in.
The text was updated successfully, but these errors were encountered: