Disallow privilege escalation in rabbitmq server container

This PS is to address security best practices in rabbitmq
server containers by disabling allowPrivilegeEscalation flag

Change-Id: I4de2ee4320efaa9569312016f4cca61c1f7636b2
This commit is contained in:
Gayathri Devi Kathiri 2021-01-29 09:37:37 +00:00 committed by Gayathri Devi Kathiri
parent 39173f27a8
commit bf41f10068
3 changed files with 7 additions and 1 deletions

View File

@ -15,6 +15,6 @@ apiVersion: v1
appVersion: v3.7.26 appVersion: v3.7.26
description: OpenStack-Helm RabbitMQ description: OpenStack-Helm RabbitMQ
name: rabbitmq name: rabbitmq
version: 0.1.5 version: 0.1.6
home: https://github.com/rabbitmq/rabbitmq-server home: https://github.com/rabbitmq/rabbitmq-server
... ...

View File

@ -84,6 +84,7 @@ pod:
runAsUser: 0 runAsUser: 0
readOnlyRootFilesystem: true readOnlyRootFilesystem: true
rabbitmq: rabbitmq:
allowPrivilegeEscalation: false
runAsUser: 999 runAsUser: 999
readOnlyRootFilesystem: false readOnlyRootFilesystem: false
cluster_wait: cluster_wait:

View File

@ -1,4 +1,9 @@
--- ---
rabbitmq: rabbitmq:
- 0.1.0 Initial Chart - 0.1.0 Initial Chart
- 0.1.1 Change helm-toolkit dependency version to ">= 0.1.0"
- 0.1.2 changes rmq-exporter secret src
- 0.1.4 Add configurable RABBIT_TIMEOUT parameter
- 0.1.5 Update Rabbitmq exporter version
- 0.1.6 Disallow privilege escalation in rabbitmq server container
... ...