Skip to content

[telemetry] limit privileged flag for telemetry container#16350

Merged
lguohan merged 1 commit intosonic-net:masterfrom
maipbui:gnmi_priv
Sep 7, 2023
Merged

[telemetry] limit privileged flag for telemetry container#16350
lguohan merged 1 commit intosonic-net:masterfrom
maipbui:gnmi_priv

Conversation

@maipbui
Copy link
Contributor

@maipbui maipbui commented Aug 30, 2023

Why I did it

HLD implementation: Container Hardening (sonic-net/SONiC#1364)

Work item tracking
  • Microsoft ADO (number only): 14807420

How I did it

Reduce linux capabilities in privileged flag

How to verify it

Which release branch to backport (provide reason below if selected)

  • 201811
  • 201911
  • 202006
  • 202012
  • 202106
  • 202111
  • 202205
  • 202211
  • 202305

Tested branch (Please provide the tested image version)

Description for the changelog

Link to config_db schema for YANG module changes

A picture of a cute animal (not mandatory but encouraged)

@maipbui maipbui marked this pull request as ready for review September 6, 2023 15:02
@lguohan lguohan merged commit e07d435 into sonic-net:master Sep 7, 2023
@maipbui maipbui deleted the gnmi_priv branch September 7, 2023 19:09
sonic-otn pushed a commit to sonic-otn/sonic-buildimage that referenced this pull request Sep 20, 2023
qiluo-msft added a commit to qiluo-msft/sonic-buildimage that referenced this pull request Sep 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants