Skip to content

[docker-pmon] limit privileged flag for pmon container#78

Closed
DavidZagury wants to merge 9 commits intomasterfrom
master_pmon_harden
Closed

[docker-pmon] limit privileged flag for pmon container#78
DavidZagury wants to merge 9 commits intomasterfrom
master_pmon_harden

Conversation

@DavidZagury
Copy link
Owner

Why I did it

HLD implementation: Container Hardening (sonic-net/SONiC#1364)

Work item tracking
  • Microsoft ADO (number only):

How I did it

Reduce linux capabilities in privileged flag

How to verify it

Run platform tests.
Check container's settings: Privileged is false and container only has default Linux caps, and SYS_RAWIO/SYS_ADMIN cap.

Which release branch to backport (provide reason below if selected)

  • 202205
  • 202211
  • 202305
  • 202311
  • 202405
  • 202411
  • 202505

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@DavidZagury DavidZagury force-pushed the master_pmon_harden branch 2 times, most recently from cb29428 to acd72c6 Compare August 4, 2025 15:08
DavidZagury pushed a commit that referenced this pull request Dec 6, 2025
…ly (sonic-net#24654)

#### Why I did it
src/sonic-stp
```
* 6be3721 - (HEAD -> master, origin/master, origin/HEAD) Correcting stp-stpmgrd IPC data structure similar to structure defined in stpmgr.h file (#80) (4 days ago) [Divya Kumaran Chandralekha]
* e80c7be - [stpctl] stpctl enhancements for mstp debugging commands (#79) (5 days ago) [vganesan-nokia]
* bfcb492 - [mstp] Fix for port enable handlinging and rx pkt type check (#78) (5 days ago) [vganesan-nokia]
```
#### How I did it
#### How to verify it
#### Description for the changelog
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants