SeccompãµããŒãã¯ãseccompãããã¡ã€ã«ãå®çŸ©ãããããã®ãããã¡ã€ã«ã§å®è¡ããããã«ããããæ§æããæ©èœãæäŸããŸãã ããã«ã¯ãPSPãä»ããŠãããã¡ã€ã«ã®äœ¿çšãå¶åŸ¡ããæ©èœãããã³å¶éãªãã§ããŸãã¯ããã©ã«ãã®ã³ã³ãããŒã©ã³ã¿ã€ã ãããã¡ã€ã«ã䜿çšããŠå®è¡ããæ©èœãç¶æããæ©èœãå«ãŸããŸãã
KEPïŒ sig-node / 20190717-seccomp-ga.md
KEPãæŽæ°ããããã®ææ°ã®PRïŒïŒ1747
/pkg/apis/...
ïŒ@kubernetes/api
@kubernetes/docs
@kubernetes/feature-reviewers
@kubernetes/docs
@kubernetes/feature-reviewers
@kubernetes/api
@kubernetes/feature-reviewers
@kubernetes/docs
@kubernetes/feature-reviewers
_FEATURE_STATUSã¯ãæ©èœã®è¿œè·¡ã«äœ¿çšããã @kubernetes/feature-reviewers
ã«ãã£ãŠæŽæ°ãããŸãã_
FEATURE_STATUSïŒIN_DEVELOPMENT
ãã®ä»ã®ã¢ããã€ã¹ïŒ
èšèš
@kubernetes/feature-reviewers
_ã¡ã³ããŒããLGTMãååŸãããããã®ãã§ãã¯ããã¯ã¹ããªã³ã«ãããšãã¬ãã¥ãŒæ
åœè
ã¯ããã¶ã€ã³å®äºãã©ãã«ãé©çšããŸããã³ãŒãã£ã³ã°
@kubernetes/feature-reviewers
èšåããã³ã¡ã³ããè¿œå ããŠãã ãããããã¥ã¡ã³ã
@kubernetes/docs
èšåããã³ã¡ã³ããè¿œå ããŠãã ããã@derekwaynecarr @sttts @erictuneã¯ãã®åé¡ã
@stttsããã¥ã¡ã³ããšPRãžã®é©åãªãªã³ã¯ãæäŸã§ããŸããïŒ ç§ã¯ããªãããã®ã³ãŒãã«æãè¿ããšæããŸãã
@ pweil- @sttts -æã ã®è°è«ããšã«ãããã¯æã ã@ kubernetes / SIG-ããŒãã®äžKubernetes 1.6ã«ã¹ãã³ãµãŒãããæ©èœã§ã
@ pweil- @derekwaynecarr ããã®æ©èœã1.6ãã€ã«ã¹ããŒã³ã«èšå®ããå¿ èŠãããããšã確èªããŠãã ããã
@ idvoretskyi1.6ã®ããŒã¿çã«ç§»è¡ããããšãç®æšãšããŠããŸãã
@stttsããããšãã
ããã¯ãŸã ã¢ã«ãã¡ã®ããã§ãïŒ
https://github.com/kubernetes/community/blob/master/contributors/design-proposals/seccomp.md
https://github.com/kubernetes/kubernetes/blob/master/pkg/api/annotation_key_constants.go#L35
ãŸããkubernetes.io / docsã«ããã¥ã¡ã³ããèŠã€ãããŸããã§ããã
@ pweil- 1.8ã®ã¢ããããŒãã¯ãããŸããïŒ ãã®æ©èœã¯ãŸã ãªãªãŒã¹ã«åããŠé 調ã«é²ãã§ããŸããïŒ
@idvoretskyiããã¯1.8ã®åªå äºé ã§ã¯ãããŸããã§ããã @ php-coder PMèšç»ã®ããã«ãããã«ã«ãŒããè¿œå ã§ããŸããïŒ ãããã¯ã©ãã¯ã«é¥ãããã®ããããããŒã¿çãšGAã«ç§»è¡ããå¿ èŠããããŸãã
@ pweil-ãã®æ©èœã1.8ã§èšç»ãããŠããªãå Žåã¯ããã€ã«ã¹ããŒã³ãã次ã®ãã€ã«ã¹ããŒã³ããŸãã¯ã1.9ãã§æŽæ°ããŠãã ãã
ãããããŒã¿çã«ãªãã®ãèŠããã§ãã ãã®ããã®åªå é äœïŒãŸãã¯èŠä»¶ïŒã«ã¯ã次ã®ãã®ãå«ãŸããŸãã
SecurityContext
ãã£ãŒã«ãã«ç§»åããå¿
èŠããããŸãïŒhttps://github.com/kubernetes/community/blob/master/contributors/devel/api_changes.md#alpha-field-ãåç
§ïŒæ¢åã®APIããŒãžã§ã³ïŒdocker/default
ã¯åŒãç¶ãèš±å¯ãããŸãïŒäžäœäºææ§ã®ããïŒ1.9ïŒãŸãã¯1.10ïŒãã€ã«ã¹ããŒã³ã§ãã®äœæ¥ãæšé²ããããšã«èå³ããã人ã¯ããŸããïŒ @jessfraz @ kubernetes / sig-auth-feature-requestsããã³@kubernetes / sig-node-feature-requestsç§ã¯ããªããèŠãŠããŸãïŒwinkïŒ
é¢é£é ç®ïŒ https ïŒ
/ cc @destijl
誰ããæéããããããããããããšæã£ãŠãããªãã圌ãã¯å€§æè¿ã§ãããããŠç§ã¯
ã©ããªè³ªåã«ãçããã®ã«åœ¹ç«ã¡ãŸã
2017幎9æ22æ¥20:54ããTim AllclairïŒSt.ClairïŒã [email protected]
æžããŸããïŒ
/ cc @destijl https://github.com/destijl
â
ããªããèšåãããã®ã§ããªãã¯ãããåãåã£ãŠããŸãã
ãã®ã¡ãŒã«ã«çŽæ¥è¿ä¿¡ããGitHubã§è¡šç€ºããŠãã ãã
https://github.com/kubernetes/features/issues/135#issuecomment-331593048 ã
ãŸãã¯ã¹ã¬ããããã¥ãŒãããŸã
https://github.com/notifications/unsubscribe-auth/ABYNbDldlrwbOP75Y2AKM-bUFLnwrq0eks5slFbcgaJpZM4KgBy_
ã
ããããŸãããä»ã«èª°ãããªãå Žåã¯ãææ¡ãæŽæ°ããŠææ¥ããéå§ããŸã;ïŒ
90æ¥éæäœããªããšãåé¡ã¯å€ããªããŸãã
/remove-lifecycle stale
ããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
å€ãåé¡ã¯ãããã«30æ¥ééã¢ã¯ãã£ãã«ãªããšè
æããæçµçã«ã¯éããŸãã
/lifecycle frozen
ã³ã¡ã³ãã䜿çšããŠãåé¡ãèªåçµäºããªãããã«ããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã
sig-testingãkubernetes / test-infraãããã³/ãŸãã¯@fejta
ãã£ãŒãããã¯ãéä¿¡ããŸãã
/ lifecycle stale
ãã@jessfrazããªããããã«ã€ããŠã©ããã«è¡ã£ããã©ããããããªã-ç§ã¯ãããã³ãŒãã£ã³ã°ããããã®åž¯åå¹ ãæã£ãŠããŸãããããã¹ããæäŒã£ãŠå¹žãã§ã...
å€ããªã£ãåé¡ã¯ã30æ¥éæäœããªããšè
æããŸãã
/remove-lifecycle rotten
ããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
è
ã£ãåé¡ã¯ãããã«30æ¥éæäœããªããšçµäºããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã
SIG-ãã¹ããkubernetes /ãã¹ãã»ã€ã³ãã©ããã³/ãŸãã¯ãžã®ãã£ãŒãããã¯ãéä¿¡fejta ã
/ã©ã€ããµã€ã¯ã«è
æ
/ remove-lifecyclestale
è
ã£ãåé¡ã¯ã30æ¥éæäœããªããšçµäºããŸãã
/reopen
åé¡ãåéããŸãã
/remove-lifecycle rotten
ããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
SIG-ãã¹ããkubernetes /ãã¹ãã»ã€ã³ãã©ããã³/ãŸãã¯ãžã®ãã£ãŒãããã¯ãéä¿¡fejta ã
/éžã¶
/ reopen
/ã©ã€ããµã€ã¯ã«åçµ
/ remove-lifecycle rotten
@ php-coderïŒäœæããããå²ãåœãŠãããŠããªãéãã課é¡/ PRãå床éãããšã¯ã§ããŸããã
察å¿ããŠããã®ïŒ
/ reopen
/ã©ã€ããµã€ã¯ã«åçµ
/ remove-lifecycle rotten
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
/ reopen
/ã©ã€ããµã€ã¯ã«åçµ
7:07ã§æã2018幎3æ26æ¥ã«ã¯ãK8S-CI-ãããã[email protected]
æžããŸããïŒ
@ php-coder https://github.com/php-coder ïŒåé¡/ PRãå床éãããšã¯ã§ããŸãã
ããªãããããäœæããããããªããããã«å²ãåœãŠãããŠããªãéããããã«å¿ããŠ
https://github.com/kubernetes/features/issues/135#issuecomment-376129291
ïŒ/ reopen
/ã©ã€ããµã€ã¯ã«åçµ
/ remove-lifecycle rottenPRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ãã¡ãããå ¥æã§ããŸã
https://git.k8s.io/community/contributors/devel/pull-requests.md ã ããã
ç§ã®è¡åã«é¢é£ãã質åãææ¡ããããŸãããã
kubernetes / test-infraã«å¯Ÿããåé¡
https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issueïŒ
ãªããžããªãâ
ããªãã¯èšåãããããŒã ã«æå±ããŠããã®ã§ããããåãåã£ãŠããŸãã
ãã®ã¡ãŒã«ã«çŽæ¥è¿ä¿¡ããGitHubã§è¡šç€ºããŠãã ãã
https://github.com/kubernetes/features/issues/135#issuecomment-376129294 ã
ãŸãã¯ã¹ã¬ããããã¥ãŒãããŸã
https://github.com/notifications/unsubscribe-auth/ABG_p9EwKebniej_GySRKSvzrCMITOA1ks5tiMvrgaJpZM4KgBy_
ã
@smarterclayton ïŒäœæããããå²ãåœãŠãããŠããªãéãã課é¡/ PRãå床éãããšã¯ã§ããŸããã
察å¿ããŠããã®ïŒ
/ reopen
/ã©ã€ããµã€ã¯ã«åçµ7:07ã§æã2018幎3æ26æ¥ã«ã¯ãK8S-CI-ãããã[email protected]
æžããŸããïŒ@ php-coder https://github.com/php-coder ïŒåé¡/ PRãå床éãããšã¯ã§ããŸãã
ããªãããããäœæããããããªããããã«å²ãåœãŠãããŠããªãéããããã«å¿ããŠ
https://github.com/kubernetes/features/issues/135#issuecomment-376129291
ïŒ/ reopen
/ã©ã€ããµã€ã¯ã«åçµ
/ remove-lifecycle rottenPRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ãã¡ãããå ¥æã§ããŸã
https://git.k8s.io/community/contributors/devel/pull-requests.md ã ããã
ç§ã®è¡åã«é¢é£ãã質åãææ¡ããããŸãããã
kubernetes / test-infraã«å¯Ÿããåé¡
https://github.com/kubernetes/test-infra/issues/new?title=Prow%20issueïŒ
ãªããžããªãâ
ããªãã¯èšåãããããŒã ã«æå±ããŠããã®ã§ããããåãåã£ãŠããŸãã
ãã®ã¡ãŒã«ã«çŽæ¥è¿ä¿¡ããGitHubã§è¡šç€ºããŠãã ãã
https://github.com/kubernetes/features/issues/135#issuecomment-376129294 ã
ãŸãã¯ã¹ã¬ããããã¥ãŒãããŸã
https://github.com/notifications/unsubscribe-auth/ABG_p9EwKebniej_GySRKSvzrCMITOA1ks5tiMvrgaJpZM4KgBy_
ã
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
/ reopen
@idvoretskyi ïŒäœæããããå²ãåœãŠãããŠããªãéãã課é¡/ PRãå床éãããšã¯ã§ããŸããã
察å¿ããŠããã®ïŒ
/ reopen
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
Ihor 1ãããã0
@ pweil- @ php-coder @jessfraz
1.11ã§ããã«ã€ããŠäœãèšç»ã¯ãããŸããïŒ
ãããããªããããªãã¯ãã®æ©èœãé©åãªãã®ã§ææ°ã§ããããšã確èªããŠãã ããïŒ
stage/{alpha,beta,stable}
sig/*
kind/feature
cc @idvoretskyi
@ wangzhen127ã¯çŸåšåãçµãã§ããŸããããŸã ã¡ã³ããŒã§ã¯ãªããããå²ãåœãŠãããšãã§ããŸããã
https://github.com/kubernetes/kubernetes/pull/62662
https://github.com/kubernetes/kubernetes/pull/62671
æŽæ°ããŠãããŠããããšãããã£ã ïŒ
/ remove-ã©ã€ããµã€ã¯ã«ãåçµãããŸãã
@ pweil- @tallclair -ç§ãã¡ã¯ãã®1åã®ä»¥äžã®æåŒãã£ãŠããã¹ãã¬ããã·ãŒãã远跡1.11ç¹é·ã
ãã®æ©èœã®åºåç³èŸŒæ
å ±ã®äžå®å
šãª/空çœã®ãã£ãŒã«ãã«å
¥åããŠããã ããŸãããã
@ pweil- @tallclair -äœã®æŽæ°ãé²è¡ããªãããããã¥ã¡ã³ãWRTããã£ããšããŠããã®æ©èœã¯ã1.11ãã€ã«ã¹ããŒã³ããåé€ãããŸããã
ccïŒ @jberkus
@ pweil- @tallclair @ kubernetes / sig-auth-feature-requests @ kubernetes / sig-node-feature-requests-
ãã®æ©èœã¯ä»¥åã®ãã€ã«ã¹ããŒã³ããåé€ãããããããã§ãã¯ã€ã³ããŠãKubernetes1.12ã§ãã®æ©èœã®èšç»ããããã©ããã確èªããããšæããŸãã
ãã®å Žåã¯ã次ã®ãã¹ãŠã®æ å ±ã䜿çšããŠããã®åé¡ãææ°ã§ããããšã確èªããŠãã ããã
ããããŒã·ããã³ã°ïŒ
/ cc @justaugustus @ kacole2 @robertsandoval @ rajendar38
1.12ã®å€æŽã¯äºå®ãããŠããŸãã
æŽæ°ããŠãããŠããããšãã@ tallclairïŒ
1.9ïŒãŸãã¯1.10ïŒãã€ã«ã¹ããŒã³ã§ãã®äœæ¥ãæšé²ããããšã«èå³ããã人ã¯ããŸããïŒ @jessfraz @ kubernetes / sig-auth-feature-requestsããã³@kubernetes / sig-node-feature-requestsç§ã¯ããªããèŠãŠããŸããŠã£ã³ã¯
@tallclairããã§ãæãŸããå Žåã¯ãä»ãããããæŸãããšãã§ããŸã
@stlaz ïŒéç¥ãããªã¬ãŒããããã«èšåãç¹°ãè¿ããŸãïŒ
@ kubernetes / sig-auth-feature-requestsã@ kubernetes / sig-node-feature-requests
察å¿ããŠããã®ïŒ
1.9ïŒãŸãã¯1.10ïŒãã€ã«ã¹ããŒã³ã§ãã®äœæ¥ãæšé²ããããšã«èå³ããã人ã¯ããŸããïŒ @jessfraz @ kubernetes / sig-auth-feature-requestsããã³@kubernetes / sig-node-feature-requestsç§ã¯ããªããèŠãŠããŸããŠã£ã³ã¯
@tallclairããã§ãæãŸããå Žåã¯ãä»ãããããæŸãããšãã§ããŸã
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
@stlaz ããã®æ©èœã¯ãŸã å¿ èŠã§ãã ïŒ39845ã®æåã®ã¹ããããšããŠãã¢ããªã³ã«seccompãããã¡ã€ã«ãè¿œå ããããšã«æéãè²»ãããŸããã ãããããã®æ©èœãããã·ã¥ããã®ã«ååãªæéããããŸããã ããªããããã«åãçµãã®ã奜ããªãããã¯çŽ æŽãããã§ãããã ã©ããªå©ãã§ã倧æè¿ã§ãïŒ :)
@ wangzhen127ããããšããç§ã¯ãã®æ©èœã«é¢é£ããŠè¡ãããããšãšéãããåé¡ãhttps://github.com/kubernetes/features/issues/135#issuecomment-331592961ã¯ãŸã ä¿æãããŠãããä»å®è¡ããå¿ èŠã®ããäœæ¥ãæ£ç¢ºã«èŠçŽããŠããããã§ãã
ãŸããããã«FeatureGateãè¿œå ããããšããŠããããšã«æ°ã¥ããŸããããPRãéããŸãããããã¯ãªãã§ããïŒ
PSïŒå¿çãé ããŠç³ãèš³ãããŸããããç§ã¯å°ãäžåšã§ããã
ã³ã¡ã³ãïŒ135ïŒã³ã¡ã³ãïŒã¯ãŸã ä¿æãããŠãããä»å®è¡ããå¿ èŠã®ããäœæ¥ãæ£ç¢ºã«èŠçŽããŠããããã«æãããŸãã
ããã§ãã ç§ãè¿œå ãããããäžã€ã®ããšã¯ããèŠæ ãã¢ãŒããæã€ããšã§ãã ãã®ããããŠãŒã¶ãŒã¯ã匷å¶çµäºããã®ã§ã¯ãªããçŠæ¢ãããŠããã·ã¹ãã ã³ãŒã«ã䜿çšãããšããèŠåãïŒãã°ã§ïŒååŸããããšãéžæã§ããŸãã ãã®ã³ã°seccompã¢ã¯ã·ã§ã³ã¯ãLinuxã«ãŒãã«4.14以éïŒ seccomp doc ïŒã§äœ¿çšã§ããŸãã å€ãã«ãŒãã«ããŒãžã§ã³ããŸã 䜿çšãããŠããå¯èœæ§ããããŸãã ãããã£ãŠããããåŠçããå¿ èŠããããŸãã ãããOCIä»æ§ã«è¿œå ããå¿ èŠããããŸãã
ãŸããããã«FeatureGateãè¿œå ããããšããŠããããšã«æ°ã¥ããŸããããPRãéããŸãããããã¯ãªãã§ããïŒ
ãã®æ©èœã²ãŒãã®ç®çã¯ãseccompã®ããã©ã«ããããã¡ã€ã«ãéå¶éãããã©ã³ã¿ã€ã /ããã©ã«ããã«å€æŽããããšã§ããã äžäœäºææ§ã«ã€ããŠå€ãã®æžå¿µããã£ãã®ã§ããããªãå¯èœæ§ã¯äœãããã§ããã çŸåšãã»ãã¥ãªãã£ã®ããã©ã«ããå£ããŠãããããäžè¬çã«ã»ãã¥ãªãã£ã®ããã©ã«ããå€æŽããèšç»ã¯ãããŸããã ç§ãçŸåšèããŠããæåã®ã¢ãããŒãã¯ãseccompãå®å®ãããããšã§ãããããã§ããªããã¢ãŠãã§ã¯ãªããªããã€ã³æ©èœã§ããå¿ èŠããããŸãã
ãã®ã³ã°seccompã¢ã¯ã·ã§ã³ã¯ãLinuxã«ãŒãã«4.14以éïŒ seccomp doc ïŒã§äœ¿çšã§ããŸãã
2çªç®ã®ã¹ãããã®äžéšãšããŠKubernetesåºæã®ããã©ã«ãã®seccomp圢åŒãå®çŸ©ããã®ã§ã代ããã«ãã°ãèšé²ãã圢åŒã䜿çšããããšãã§ããŸãã ããã«ã¯ååãªäŸ¡å€ããããŸããïŒ åŸè
ã倱æãããããšãã«ã人ã
ããå¶éãªãããããkube / defaultãã«ç§»è¡ããããã«äœ¿çšã§ããŸããïŒ åœŒãã¯ãããã¹ã€ããããã¹ã€ããããã¯ã«åãæ¿ããã®ãæ°ã«ãããŸããïŒ
4.13- Linuxã«ãŒãã«ïŒDebian-8,9; RHEL-6,7; Ubuntu LTS-14.04,16.04ïŒã䜿çšããLTSãã£ã¹ããªãã¥ãŒã·ã§ã³ãããã®ã§ãã«ãŒãã«ã®äºææ§ã¯ééããªãèŠããŠããã¹ããã®ã§ãã
äžäœäºææ§ã«ã€ããŠå€ãã®æžå¿µããã£ãã®ã§ããããªãå¯èœæ§ã¯äœãããã§ããã
ã³ã³ããã©ã³ã¿ã€ã ã¯ãseccompãåããŠæå¹ã«ãããšãã«ãéå»ã«ããã®å€æŽãè¡ãå¿ èŠããããŸããã çŸåšãå°ãªããšãdockerã¯ã誰ããå£ããå¯èœæ§ã®ãããå¶éãªãããããèš±å¯ãããŠããªãããã©ã«ãã®åäœã§åºè·ãããŸãã åºç€ãšãªãã³ã³ããŒãã³ãã®åäœïŒãã®åäœããªãã«ããéžæè¢ãæäŸããŸãïŒã«åŸãã ãã§ãäœãæªãããšãããŠãããšã¯æããŸããã
ããã«ã¯ååãªäŸ¡å€ããããŸããïŒ
ããã¯è°è«ããããšãã§ããŸãã ç§ã®åœåã®èãã¯ãããã©ã«ããå¶éãªããããã®ã³ã°ã«å€æŽããããšã§ããã ãããã£ãŠãäžäœäºææ§ã®åé¡ã¯ãããŸããã ãããŠããªãããã®æ¹æ³ã§ããŒã¿ãåéããXïŒ ã®ã±ãŒã¹ã§äœããã°ã«èšé²ãããŠããªãããšã瀺ãããšãã§ããã°ãããã©ã«ãã®ãããã¡ã€ã«ã§åé¡ãçºçããããšã¯ãããŸããã 次ã«ããã°ãkillã«å€æŽããããšãææ¡ã§ããŸãã ããŒã¿éšåã®åéã¯ããªãããŒã§ãå€ãã®äœæ¥ã«ãªãå¯èœæ§ããããŸãã ç§ãã¡ãå®éã«ãã®ã«ãŒãã«è¡ããªããŠãããã®ã³ã°ãããã¡ã€ã«ãæã€ããšã¯ãseccompãè©ŠããŠã¿ãããããŸã èªä¿¡ããªãå Žåã«åœ¹ç«ã€ãšæããŸãã
ã³ã³ããã©ã³ã¿ã€ã ã¯ãseccompãåããŠæå¹ã«ãããšãã«ãéå»ã«ããã®å€æŽãè¡ãå¿ èŠããããŸããã çŸåšãå°ãªããšãdockerã¯ã誰ããå£ããå¯èœæ§ã®ãããå¶éãªãããããèš±å¯ãããŠããªãããã©ã«ãã®åäœã§åºè·ãããŸãã åºç€ãšãªãã³ã³ããŒãã³ãã®åäœïŒãã®åäœããªãã«ããéžæè¢ãæäŸããŸãïŒã«åŸãã ãã§ãäœãæªãããšãããŠãããšã¯æããŸããã
dockerãããã©ã«ãå€ãå€æŽãããšãkubernetesã¯ãã®ãããªå€ãæ瀺çã«unconfinedã«ãªã»ããããŸãã ç§ã¯ä»¥åã«ãªãã©ã€ã³ã§sig-architectureã®äººã ã«é£çµ¡ãåããŸãããã圌ãã¯äžäœäºææ§ã®åé¡ã«ã€ããŠéåžžã«å¿é ããŠããŸãã
ãããŠããªãããã®æ¹æ³ã§ããŒã¿ãåéããXïŒ ã®ã±ãŒã¹ã§äœããã°ã«èšé²ãããŠããªãããšã瀺ãããšãã§ããã°ãããã©ã«ãã®ãããã¡ã€ã«ã§åé¡ãçºçããããšã¯ãããŸããã
ç§ã¯ãã®èãã奜ãã§ãã é£ããã®ã¯ãã¡ããããŒã¿ãååŸããããšã§ããã©ããã£ãŠããŒã¿ãååŸããã®ãããããŸããã ãŸããæåã«ãã®å€æŽãOCIä»æ§ã«ææ¡ããŠãããå°ãªããšã1ã€ã®ã³ã³ãããŒã©ã³ã¿ã€ã ã«å®è£ ããå¿ èŠããããŸããã ã©ã€ããµã€ã¯ã«ã®ããŒã¿éšåã§ãããçºçããŠãåé¡ãããŸãããïŒ
dockerãããã©ã«ãå€ãå€æŽãããšãkubernetesã¯ãã®ãããªå€ãæ瀺çã«unconfinedã«ãªã»ããããŸãã ç§ã¯ä»¥åã«ãªãã©ã€ã³ã§sig-architectureã®äººã ã«é£çµ¡ãåããŸãããã圌ãã¯äžäœäºææ§ã®åé¡ã«ã€ããŠéåžžã«å¿é ããŠããŸãã
åãããŸããã ãããããããã©ã«ãã®ãããã¡ã€ã«ãšããŠãå¶éãããŠããªãããããã¡ã€ã«ã䜿çšããããšãã§ããŸãïŒåŸã§kube/logging
ãããªãã®ã«çœ®ãæããå¯èœæ§ããããŸãïŒã ãã®å Žåãããã¯æåŠã«ãŒã«ã®æ¹æ³ã§PSPã«ãã£ãŠå¶åŸ¡ãããå¯èœæ§ãããããã§ããããã§ã¯ããã¹ãŠãããã©ã«ãã§èš±å¯ãããŠãããšããåæããå§ããŠãç¹æš©ãããã«åæžããã ãã§ãã ããããã©ã°ã§å¶åŸ¡ããããšã¯ãPSPããªãã«ãªã£ãŠããå Žåã«åœ¹ç«ã€å¯èœæ§ããããŸãããã®ãããPSPã䜿çšããå¿
èŠããããŸãããããã2ã€ã®ã¡ã«ããºã ãåæã«äœ¿çšããã®ã¯å°ãé¢åã§ãã
åœåèããŠããæ¹åãšã¯å°ãéããšæããŸããhttpsïŒ//github.com/kubernetes/kubernetes/issues/39845ã§è¡ãããäœæ¥ã«åãruntime/default
ã kube/default
ã kube/logging
ãšããããã¡ã€ã«ãunconfined
ã«èšå®ãããªãã·ã§ã³ã衚瀺ãããŠããŸãã æ®ãã¯ãã¡ãããçŸåšã®å®è£
ã«ãã£ãŠãã§ã«æäŸãããŠããlocalhost/.*
ãããã¡ã€ã«ãæã€æ©èœã§ãã
ã©ã€ããµã€ã¯ã«ã®ããŒã¿éšåã§ãããçºçããŠãåé¡ãããŸãããïŒ
ç§ã«ã¯ããã§ããã OCIä»æ§ã®ææ¡ãæ©æã«éå§ããããšã¯åœ¹ç«ã€ãšæããŸããã
ä»ã®ãšããããã©ã«ãã¯ç§ã«ã¯è¯ããšæãã®ã§ããå¶éãªããã§è¡ã£ãŠãã ããã kubernetes / kubernetesïŒ39845ã®å Žåãã¢ããªã³ã«ã¢ãããŒã·ã§ã³ãè¿œå ããŸããã ãããŠãç§ãã¡ã¯ãã以äžé²ãããšãã§ããªããšæããŸãã
ãããŸã§ã®ãšãããruntime / defaultãkube / defaultãkube / loggingãšããããã¡ã€ã«ãunconfinedã«èšå®ãããªãã·ã§ã³ã衚瀺ãããŠããŸãã æ®ãã¯ãã¡ãããçŸåšã®å®è£ ã«ãã£ãŠãã§ã«æäŸãããŠããlocalhost /.*ãããã¡ã€ã«ãæã€æ©èœã§ãã
ç§ã®ããã«åããŸãã kube/default
å Žåã docker/default
ããå§ããããšãã§ããŸãã
ãã®ã³ã°seccompã¢ã¯ã·ã§ã³ã¯ãLinuxã«ãŒãã«4.14以éïŒseccomp docïŒã§äœ¿çšã§ããŸãã
ç§ã®ç解ã§ã¯ãããã¯PIDã䜿çšããŠã¢ã¯ã·ã§ã³ããã°ã«èšé²ããŸãããå¿ ãããã³ã³ãããŒé¢é£ã®æ å ±ã§ããå¿ èŠã¯ãããŸããã ãããã£ãŠãauditdãŸãã¯ãã¹ãäžã®ä»ã®ããŒã¢ã³ã®ãããããããã°ãæ¬åœã«åœ¹ç«ã€ããã«ã«ãã¯ã¢ãã/ãããã³ã°ãå®è¡ããå¿ èŠããããŸã...
ãããŠããªãããã®æ¹æ³ã§ããŒã¿ãåéããXïŒ ã®ã±ãŒã¹ã§äœããã°ã«èšé²ãããŠããªãããšã瀺ãããšãã§ããã°ãããã©ã«ãã®ãããã¡ã€ã«ã§åé¡ãçºçããããšã¯ãããŸããã 次ã«ããã°ãkillã«å€æŽããããšãææ¡ã§ããŸãã ããŒã¿éšåã®åéã¯ããªãããŒã§ãå€ãã®äœæ¥ã«ãªãå¯èœæ§ããããŸãã
Dockerã®dockerããã©ã«ããããã¡ã€ã«ãèµ·åãããšãã«ã
@tallclairããªããæ£ããã§ããç§ã¯ãã¹ãŠã®åé¡ã®ã³ã¡ã³ãã§ã¡ãã£ãšè¿·åã«ãªããŸããã åèãŸã§ã«ãDockerfilesããã§ãã¯ãããããšã瀺ãã³ã¡ã³ãã¯æ¬¡ã®ãšããã§ãïŒ https ïŒ//github.com/kubernetes/community/pull/660#issuecomment-303860107ã çµå±ã®ãšãããã殺害ãã®ããã©ã«ããèšå®ããŠãå®å šã ãšæããŸãã
ãã
ãã®æ¡åŒµæ©èœã¯ä»¥åã«è¿œè·¡ãããŠããããããã§ãã¯ã€ã³ããŠãKubernetes1.13ã®ã¹ããŒãžãåæ¥ããèšç»ããããã©ããã確èªããããšæããŸãã ãã®ãªãªãŒã¹ã¯ããããå®å®ãããããšãç®çãšããŠãããç©æ¥µçãªã¿ã€ã ã©ã€ã³ããããŸãã 次ã®æéã«éã«åããšç¢ºä¿¡ã§ããå Žåã«ã®ã¿ããã®æ¡åŒµæ©èœãå«ããŠãã ããã
1.13æ¡åŒµãã©ããã³ã°ã·ãŒãã«å«ããå¿ èŠãããå Žåã¯ãä»åŸã®è¿œè·¡ãšping @ kacole2ã®ããã«ãå ã®æçš¿ã®ãã€ã«ã¹ããŒã³ãæŽæ°ããŠãã ããã
ããããšãïŒ
90æ¥éæäœããªããšãåé¡ã¯å€ããªããŸãã
/remove-lifecycle stale
ããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
å€ãåé¡ã¯ãããã«30æ¥ééã¢ã¯ãã£ãã«ãªããšè
æããæçµçã«ã¯éããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã
SIG-ãã¹ããkubernetes /ãã¹ãã»ã€ã³ãã©ããã³/ãŸãã¯ãžã®ãã£ãŒãããã¯ãéä¿¡fejta ã
/ lifecycle stale
kubernetes/enhancements
éãããæ¡åŒµæ©èœã®åé¡ã¯ãããªãŒãºãšããŠããŒã¯ãããã¹ãã§ã¯ãããŸããã
æ¡åŒµæ©èœã®ææè
ã¯ããªãªãŒã¹ãµã€ã¯ã«å
šäœã§ç¶æ
ãäžè²«ããŠæŽæ°ããããšã«ãããæ¡åŒµæ©èœãææ°ã®ç¶æ
ã«ä¿ã€ããšãã§ããŸãã
/ remove-ã©ã€ããµã€ã¯ã«ãåçµãããŸãã
å€ããªã£ãåé¡ã¯ã30æ¥éæäœããªããšè
æããŸãã
/remove-lifecycle rotten
ããŠãåé¡ãæ°èŠãšããŠããŒã¯ããŸãã
è
ã£ãåé¡ã¯ãããã«30æ¥éæäœããªããšçµäºããŸãã
ãã®åé¡ãä»ãã解決ã§ããå Žåã¯ã /close
ã
SIG-ãã¹ããkubernetes /ãã¹ãã»ã€ã³ãã©ããã³/ãŸãã¯ãžã®ãã£ãŒãããã¯ãéä¿¡fejta ã
/ã©ã€ããµã€ã¯ã«è
æ
/ remove-lifecycle rotten
ããã«ã¡ã¯@ stlaz @ pweil-ãç§ã¯1.15ã®ãšã³ãã³ã¹ã¡ã³ããªãŒãã§ãã ãã®æ©èœã¯1.15ã§ã¢ã«ãã¡/ããŒã¿/å®å®ã¹ããŒãžãåæ¥ããäºå®ã§ããïŒ é©åã«è¿œè·¡ããŠã¹ãã¬ããã·ãŒãã«è¿œå ã§ããããã«ããç¥ãããã ããã ããã«ã¯ãKEPã1.15ã«å«ããå¿ èŠããããŸãã
ã³ãŒãã£ã³ã°ãéå§ããããé©åã«è¿œè·¡ã§ããããã«ããã®å·ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã
1.15ã®å€æŽã¯äºå®ãããŠããŸãã
ããã«ã¡ã¯@ tallclair @ pweil- @stlaz ãç§ã¯1.16ãšã³ãã³ã¹ã¡ã³ããªãŒã/ã·ã£ããŠã§ãã ãã®æ©èœã¯1.16ã§ã¢ã«ãã¡/ããŒã¿/å®å®æ®µéãåæ¥ããäºå®ã§ããïŒ 1.16ãã©ããã³ã°ã¹ãã¬ããã·ãŒãã«è¿œå ã§ããããã«ãç¥ãããã ããã åæ¥ããŠããªãå Žåã¯ããã€ã«ã¹ããŒã³ããåé€ãã远跡ã©ãã«ãå€æŽããŸãã
ã³ãŒãã£ã³ã°ãéå§ããããããŸãã¯ãã§ã«éå§ãããŠããå Žåã¯ãé©åã«è¿œè·¡ã§ããããã«ããã®å·ã«é¢é£ãããã¹ãŠã®k / kPRããªã¹ãããŠãã ããã
泚æãšããŠããã¹ãŠã®æ¡åŒµã«ã¯ãåã¢ã«ãã¡/ããŒã¿/å®å®ã¹ããŒãžã®èŠä»¶ã説æããåæ¥åºæºãåããå®è£ å¯èœãªç¶æ ã®KEPãå¿ èŠã§ãã
ãã€ã«ã¹ããŒã³ã®æ¥ä»ã¯ãEnhancement Freeze7 / 30ããã³CodeFreeze8 / 29ã§ãã
ããããšãããããŸããã
ç§ã¯ãããGAã«æã¡èŸŒãèšç»ã®å§ãŸããæã£ãŠããŸããã1.16ã§ãããå®çŸããã®ã¯é£ãããããããŸããã ãã ããæ¡åŒµæ©èœã®ããªãŒãºã«ãã£ãŠææ¡ãåºãããã«ããŸãã
ããã«ã¡ã¯@ tallclair @ pweil-ã1.17ãšã³ãã³ã¹ã¡ã³ãã·ã£ããŠã¯ãã¡ãïŒ ð
*ãã®æ¡åŒµæ©èœã1.17ã§ã¢ã«ãã¡/ããŒã¿/å®å®ã«æ®µéçã«ç§»è¡ããã§ããïŒ
ãã®æ¡åŒµæ©èœã1.17ãã©ããã³ã°ã·ãŒãã«è¿œå ã§ããããã«ããç¥ãããã ããã
ããããšãããããŸããïŒ
ðãã¬ã³ããªãŒãªãªãã€ã³ããŒ
Kubernetesæ¡åŒµããããŒã¶ã«ïŒKEPïŒã¯ãæ¡åŒµããªãŒãºããªãªãŒã¹ã«åãå ¥ãããã
implementable
ç¶æ
ã®å Žåé¢é£ãããã¹ãŠã®k / kPRããã®å·ã«èšèŒããå¿ èŠããããŸã
ã¯ãããããv1.17ã§å®å®ããããã«åæ¥ããäºå®ã§ã-KEPã¯ãã¡ãïŒ https ïŒ
ãã@tallclair ã远跡ãã远跡ã·ãŒãã«ãã®æ¡åŒµæ©èœãè¿œå ããŸãð
ãããããããªãã€ã³ããŒã«ã€ããŠã¯äžèšã®ã¡ãã»ãŒãžãåç §ããŠãã ãããKEPã¯æ«å®çãªç¶æ ã§ããããšã«æ³šæããŠãã ããã KEPã¯ã1.17ãªãªãŒã¹ã«è¿œå ããããã«å®è£ å¯èœãªç¶æ ã§ããå¿ èŠããããŸãã
/ãã€ã«ã¹ããŒã³v1.17
/ã¹ããŒãžå®å®
ãã@tallclairtestgridã®ãã¹ããžã®ãªã³ã¯ãæçš¿ããŠããã®æ¡åŒµæ©èœã®ããã«è¿œå ããããã¹ãã远跡ããŠããã ããŸãããïŒ
ããããšãããããŸããïŒ
ããŸãããã ãã§ã«ããããã®seccompãã¹ãããããŸãããããã·ã¥ããŒãã®ã¿ãã§èŠã€ããããšãã§ããŸããïŒç¹å®ã®ãã¹ãã«ã€ããŠãã¹ãŠã®ãã¹ãã°ãªãããæ€çŽ¢ããæ¹æ³ã¯ãããŸããïŒïŒ
https://github.com/kubernetes/kubernetes/blob/0956acbed17fb71e76e3fbde89f2da9f8ec8b603/test/e2e/node/security_context.go#L147 -L177
@tallclairãã¹ãŠã®testgridãæ€çŽ¢ããè¯ãæ¹æ³ã¯ãããŸãã= /
ç§ã®æåã®æšæž¬ïŒå°ãªããšãããªããåç §ãã4ã€ã«ã€ããŠïŒã¯ãããããå®éã«ã¯å«ãŸããŠããªããšããããšã§ãã ð¬
ãããã¯node-kubelet-featuresããã·ã¥ããŒãã®äžéšã§ããå¿
èŠãããããã«èŠããŸããã ci-kubernetes-node-kubelet-featuresã®ãžã§ãæ§æã«ã¯test_args
ã®ããã«ããããããŸãïŒ
--test_args=--nodes=8 --focus="\[NodeFeature:.+\]" --skip="\[Flaky\]|\[Serial\]"
ã€ãã§ãŠã®ãã¹ãèªäœã¯[Feature:Seccomp]
ã¿ã°ä»ããããŠããããã©ãŒã«ã¹ãã©ã°ã¯äžèŽããŸããã
GAã«ç§»è¡ããããæ©èœã¿ã°ãåé€ããå¿
èŠããããšæããŸãã Linuxã§ã¯seccompãæšæºã ãšæãã®ã§ã [LinuxOnly]
ã¿ã°ã§ååã§ãã
ãã¹ããå®è¡ãããªããšããäžè¬çãªåé¡ã«ã€ããŠã¯ã httpsïŒ//github.com/kubernetes/test-infra/issues/14647ãæåºããŸãã
@tallclairãããEnhancements Freeze ïŒ10æ15æ¥ç«ææ¥ãEOD PSTïŒããããã5æ¥ã§ãã 1.17ãªãªãŒã¹ã§ãããåæ¥ã§ããããã«ããã«ã¯ãKEPãããŒãžããŠãå®è£ å¯èœãªç¶æ ã«ããå¿ èŠãããããšãæãåºããŠãã ããã KEPã¯ãŸã éããŠãããæ«å®çãªç¶æ ã«ããããã§ãã
@tallclairãããæ®å¿µãªãã1.17æ¡åŒµããªãŒãºã®æéãéããŠãããKEPã¯ãŸã éããŠããããã§ãã ãã®æ¡åŒµæ©èœã1.17ãã€ã«ã¹ããŒã³ããåé€ããŸãã
1.17ã§ãããååŸããå¿ èŠãããå Žåã¯ãæ¡åŒµäŸå€ãæåºã§ããããšã«æ³šæããŠãã ããã
/ãã€ã«ã¹ããŒã³ã¯ãªã¢
ãããã«ããããŸããã§ããã ãããåãå
¥ããããšãæãã§ãã
/ãã€ã«ã¹ããŒã³v1.18
ããã§ããïŒ æ¡åŒµè¿œè·¡ã·ãŒãã§ããããv1.18ã«å»¶æããããã®ãšããŠããŒã¯ããŸãã
ããðããããåé²ãããããã«ç§ãã¡ã«ã§ããããšã¯ãããŸããïŒ ãããšAppArmorã®åé¡ã«è²¢ç®ã§ããã°å¹žãã§ãã
ãã@tallclair
1.18æ©èœåŒ·åããŒã ã®ãã§ãã¯ã€ã³ïŒ 1.18ã§å®å®ã«åæ¥ããäºå®ã§ããïŒ KEPã¯ãŸã éããŠããããã§ãã
ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
ããªãŒãºã®åŒ·åïŒ 1æ28æ¥
ã³ãŒãããªãŒãºïŒ 3æ5æ¥
ããã¥ã¡ã³ã察å¿ïŒ 3æ16æ¥
v1.18ãªãªãŒã¹ïŒ 3æ24æ¥
念ã®ãããKEPãããŒãžããŠãã¹ããŒã¿ã¹ãimplementable
èšå®ããå¿
èŠããããŸãã
ããããšãïŒ
@saschagrunertãªãã¡ãŒãããããšãïŒ @liggittã§è¡ã£ãAPIã¬ãã¥ãŒããã©ããŒã¢ããããã«ã¯ãKEPã§å¥ã®ãã¹ãååŸããå¿ èŠããããŸãã KEPãæ¿èªãããããå®è£ ã«ãååããã ããã°å¹žãã§ãã
çŸåšãKEPã§æ倧ã®æªè§£æ±ºã®è³ªåã¯ãããŒã«ã«ãã¹ããããã¡ã€ã«ã¿ã€ããåŠçããæ¹æ³ã ãšæããŸãã ãã®æ©èœãå»æ¢ãããã®ã§ïŒçæ³çã«ã¯https://github.com/kubernetes/enhancements/pull/1269ã/ cc @pjbgfã®ãããªãã®ã
ãã@tallclair ãããã1.18ã«ãªããã©ããã«ã€ããŠã®æŽæ°ã¯ãããŸããïŒ çŸåšããã€ã«ã¹ããŒã³ã§ããŒã¯ãããŠããŸãããããã远跡ããå¿ èŠããããã©ããã¯ç¢ºèªãããŠããŸããã
ããããšãïŒ
v1.18ã¯ããã«ã€ããŠã¯ããããããªãããã§ãã ç§ãã¡ã¯ã¶ã€ããããšãã§ãããšæããŸã
/ãã€ã«ã¹ããŒã³v1.19
çŽ æŽããããæŽæ°@tallclairãããããšã:)
ããã«ã¡ã¯@ tallclair -1.19æ¡åŒµæ©èœããããªãŒãããŸãããã®æ¡åŒµæ©èœããã®ãªãªãŒã¹ã§stable
ã«åæ¥ããäºå®ã¯ãããŸããïŒ
v1.19ã§åæ¥ããäºå®ã¯ãããŸããã ç§ã¯ãªãŒãã³KEPãæã£ãŠããŸãããä»ååæã¯ããã«åãçµãã§ããŸããã @pjbgfã¯
@ tallclair-æŽæ°ããŠããã ãããããšãããããŸãã ïŒslightly_smiling_faceïŒ
/ãã€ã«ã¹ããŒã³v1.20
æšæ¥ã®sig-nodeäŒè°ã§åæãããããã«ãããã«ã€ããŠã¯èšç»ã«ããããªå€æŽããããŸããã ããã¯çŸåšã次ã®ç®çã§èšç»ãããŠããŸãã
/ãã€ã«ã¹ããŒã³v1.19
@pjbgf ïŒãã€ã«ã¹ããŒã³ãèšå®ããã«ã¯ã
察å¿ããŠããã®ïŒ
æšæ¥ã®sig-nodeäŒè°ã§åæãããããã«ãããã«ã€ããŠã¯èšç»ã«ããããªå€æŽããããŸããã ããã¯çŸåšã次ã®ç®çã§èšç»ãããŠããŸãã
/ãã€ã«ã¹ããŒã³v1.19
PRã³ã¡ã³ãã䜿çšããŠç§ãšããåãããããã®æé ã¯ããã¡ãããå
¥æã§ãkubernetes / test-infraãªããžããªã«å¯ŸããŠåé¡ã
@palnabarunãã®åé¡ããã€ã«ã¹ããŒã³v1.19ã«èšå®ããŠãããããã§ããïŒ
/ assign pjbgf
/ãã€ã«ã¹ããŒã³v1.19
æŽæ°ããŠãããŠããããšã@ pjbgf @ tallclair ã ããªãã®èšç»ã«åŸã£ãŠè¿œè·¡ã·ãŒããæŽæ°ããŸããã
ã©ã®åæ¥ã¹ããŒãžãç®æããŠããã®ããKEPãžã®ãªã³ã¯ãæããŠãã ããã
ããããšãããããŸããïŒ ãã¹ãŠã®åªåã«æè¬ããŸãã ïŒslightly_smiling_faceïŒ
çŸåšã®ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
ããã«ã¡ã¯@tallclair ãæŽæ°ããŠããã ãããããšãããããŸãã ïŒ+1ïŒ
ããã«å¿ããŠãã©ããã³ã°ã·ãŒããæŽæ°ããŸããã
PSïŒKEPãšææ°ã®KEPã¢ããããŒãPRãžã®ãªã³ã¯ã䜿çšããŠåé¡ã®èª¬æãæŽæ°ããŸããã
æŽæ°ããŠãããŠããããšã@palnabarun ã ïŒ+1ïŒ
ããã«ã¡ã¯@ tallclairð1.19ããã¥ã¡ã³ãã·ã£ããŠã¯ãã¡ãïŒ 1.19ã§èšç»ãããŠãããã®æ¡åŒµäœæ¥ã«ã¯ãããã¥ã¡ã³ãã®æ°èŠãŸãã¯å€æŽãå¿ èŠã§ããïŒ
ããã¥ã¡ã³ãã®æ°èŠ/å€æŽãå¿
èŠãªå Žåã¯ã6æ12æ¥éææ¥ãŸã§ã«k / websiteïŒãã©ã³ãdev-1.19
ïŒã«å¯Ÿãããã¬ãŒã¹ãã«ããŒPRãå¿
èŠã«ãªãããšãèŠããŠãããŠãã ããã
@annajungããã¯é ãäžããããã§ãã ã¯ããseccompããã¥ã¡ã³ãã«ããã€ãã®å€æŽããããŸãã
ãããããã¯ã¢ããããŠãã@hasheddanãè¿œå ããŸãïŒhttps://github.com/kubernetes/kubernetes/issues/58211ïŒã
çŽ æŽããããã¢ããããŒãããŠãããŠããããšãïŒ ããã«å¿ããŠãã©ããã³ã°ã·ãŒããå€æŽããŸãã
k / websiteã«å¯Ÿãããã¬ãŒã¹ãã«ããŒPRãè¡ããããããç¥ãããã ããã ããããšãããããŸããïŒ
@ pjbgf-ããã«ãããã¹ãŠã®å®è£ PRã«ãªã³ã¯ããŠããã ããŸãã-k / kãŸãã¯ãã以å€ã§ããïŒ ïŒslightly_smiling_faceïŒ
çŸåšã®ãªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
@palnabarunãããçŸåšã®ãã®ã§ãïŒ
https://github.com/kubernetes/kubernetes/pull/91381
https://github.com/kubernetes/kubernetes/pull/91408
https://github.com/kubernetes/kubernetes/pull/91182
https://github.com/kubernetes/kubernetes/pull/91442
ãŸããããããã¹ãŠãå«ãå æ¬çãªåé¡ãäœæããŸããã
ããã«ã¡ã¯@ pjbgf @ hasheddan k / websiteã«å¯Ÿãããã¬ãŒã¹ãã«ããŒPRã®æéã¯ã6æ12æ¥éææ¥ã§ããPRãå®äºããããç¥ãããã ãããããããšãããããŸãã
@annajungãªãã€ã³ããŒãããããšãïŒ ãŸããªããªãŒãã³ããŸãïŒ+1ïŒ
ããã«ã¡ã¯@ pjbgf-ã¢ã³ãã¬ã©ã®åé¡ãäœæããŠããã ãããããšãããããŸãã ïŒ+1ïŒ
ç§ãã¡ã¯åãããšã远跡ããŠããŸãã ïŒslightly_smiling_faceïŒ
ããã«ã¡ã¯@ pjbgf-æ¡åŒµã®é²è¡ç¶æ³ã«ã€ããŠãã§ãã¯ã€ã³ãããã£ãã ãã§ãã
ãªãªãŒã¹ã¿ã€ã ã©ã€ã³ã¯æè¿æ¹èšãããŸããã詳现ã«ã€ããŠã¯ããã¡ããã芧ãã ããã
ãäžæãªç¹ãããããŸããããç¥ãããã ããã ïŒslightly_smiling_faceïŒ
æ¹èšããããªãªãŒã¹ã¹ã±ãžã¥ãŒã«ã¯æ¬¡ã®ãšããã§ãã
@palnabarunãæŽæ°ããŠããã ãããããšãããããŸãã ã³ãŒãã¯ã»ãŒãã¹ãŠå®äºããŠããŸãããçŸåšããã©ããŒã¢ããã¬ãã¥ãŒãåŸ ã£ãŠããŸãã å šäœçã«ãç§ãã¡ã¯ãŸã èŠæ ããè¯ãã§ãã ïŒ+1ïŒ
ããã«ã¡ã¯@ pjbgf @ hasheddan ã次ã®ç· ãåããè¿«ã£ãŠããããšãå奜çã«æãåºãããŠãããŸãã
ãã¬ãŒã¹ãã«ããŒããã¥ã¡ã³ãPRã«ããŒã¿ãå
¥åãã7æ6æ¥æææ¥ãŸã§ã«ç¢ºèªã§ããããã«ããŠãã ããã
ããã«ã¡ã¯@ pjbgf @ hasheddan ïŒwaveïŒãå®è£ é¢é£ã®å€æŽã«ã€ããŠã¯https://github.com/kubernetes/kubernetes/issues/91286ã«ãŸã 3ã€ã®ä¿çäžã®ã¢ã¯ã·ã§ã³ã¢ã€ãã ããããããã¥ã¡ã³ãçšã«1ã€ã®ä¿çäžã®ã¢ã¯ã·ã§ã³ã¢ã€ãã ãããããšãããããŸãã 圌ãã¯7æ9æ¥æšææ¥ã®ã³ãŒãããªãŒãºãéããŠããŸããšæããŸããïŒ
ããããšãããããŸããã ïŒslightly_smiling_faceïŒ
ã³ãŒãããªãŒãºã¯7æ9æ¥æšææ¥ã«EODPSTã§å§ãŸããŸã
@palnabarun docs PRã¯ã»ãšãã©æºåãã§ããŠãããseccompã®ç¹å®ã®ã¬ã€ããè¿œå ããã ãã§ãã ãã§ã«çŸåšã®å€æŽã«é¢ãã@saschagrunertããLGTMãæã£ãŠããŸãã ããã§ç§ãã¡ãè»éã«ä¹ããŠãããŠããããšã:)
ããã«ã¡ã¯@hasheddan ãäžèšã®æŽæ°ã«æè¬ããŸãã EODã«ããã¬ãã¥ãŒïŒWIPã®åé€/ãªããŒã¹/ãã¹ãŠã®æºåãã§ããŠããïŒã®æºåãããããã®ç°¡åãªãªãã€ã³ããŒã§ãã ããããšãããããŸããïŒ
@annajungãããïŒ ããããšãïŒ
@ hasheddan-æŽæ°ããŠããã ãããããšãããããŸãã ïŒç¬é¡ïŒ
@ pjbgf - httpsïŒ//github.com/kubernetes/kubernetes/issues/91286ã§ã 2ã€ã®ã³ã¢ã¢ã¯ã·ã§ã³ã¢ã€ãã ããŸã ããŒãžãããŠããããããŒãžããŒã«ã«ãå«ãŸããŠããªãããšãããããŸããã 圌ãã¯ã³ãŒãããªãŒãºã®åã«å ¥ããšæããŸããïŒ
ããããšãããããŸããã ïŒslightly_smiling_faceïŒ
@palnabarunã³ãŒããããªãŒãºããåã«ããã¹ãŠããã§ã«lgtmã«ãªã£ãŠããã®ã§ããããå®è¡ããããšããŠããŸãã ããã€ãã®äžå®å®ãªãã¹ãatmã§ããã€ãã®åé¡ãçºçããŠããŸãã ð
é ãäžããŠãããŠããããšãã
æ確ã«ããããã«ãç§ãã¡ãããŒãžããã®ãåŸ
ã£ãŠãã2ã€ã®prã¯æ¬¡ã®ãšããã§ãã
https://github.com/kubernetes/kubernetes/pull/91408ããã³https://github.com/kubernetes/kubernetes/pull/92856
åŸè ïŒhttps://github.com/kubernetes/kubernetes/pull/92856ïŒã¯æ€èšŒãã§ãã¯ã«å€±æããŠããããã§ãã https://github.com/kubernetes/kubernetes/pull/92856#issuecomment -655950700ã«ãããšãããŒãžããåã«rebase / repush / rereviewãå¿ èŠã«ãªããŸãã
@kikisdeliveryserviceã説æããããšãããããŸãã https://github.com/kubernetes/kubernetes/pull/91408ã§ã®äžå®å®ãªãã¹ãã倱æããªããªãã®ãåŸ ã£ãŠã
ããã«ã¡ã¯@pjbgf ïŒwaveïŒãç§ãã¡ã¯ä»ã³ãŒãããªãŒãºã«å ¥ã£ãŠããŸãã
以æ¥ã httpsïŒ//github.com/kubernetes/kubernetes/pull/91408ã¯ããŒãžããŒã«ã«ããã httpsïŒ//github.com/kubernetes/kubernetes/pull/92856ã§ã¯https://github.com/ãä»ããŠãªããŒã¹ããå¿ èŠãããhttps://github.com/kubernetes/kubernetes/pull/92856#issuecomment -655950700ã«ãããšãããã§ã®æåã®ã¢ã¯ã·ã§ã³ã¯ã2çªç®ã®å®äºã«è¿œå ã®æéãååŸããããã®äŸå€ãªã¯ãšã¹ããæåºããããšã§ããããŒãžããŒã«ãã¯ãªã¢ãããåŸã®PRã
åœé¢ããã€ã«ã¹ããŒã³ããæ¡åŒµæ©èœãåé€ããŸãã
ããããšãããããŸããïŒ
äžçªã
Kubernetesv1.19ãªãªãŒã¹æ¡åŒµããŒã
/ãã€ã«ã¹ããŒã³ã¯ãªã¢
kubernetes / kubernetesïŒ91408ã¯ããŒãžããŒã«ã«ãããkubernetes / kubernetesïŒ92856ã¯kubernetes / kubernetesïŒ92856ïŒã³ã¡ã³ãïŒã«åŸã£ãŠkubernetes / kubernetesïŒ91408ããªããŒã¹ããå¿ èŠããããããããã§ã®æåã®ã¢ã¯ã·ã§ã³ã¯äŸå€ãæåºããããšã ãšèããŠããŸãããŒãžããŒã«ãã¯ãªã¢ãããåŸã2çªç®ã®PRãå®äºããããã«è¿œå ã®æéãååŸããããã«èŠæ±ããŸãã
ããŒãžãã¥ãŒã§æ¿èªãããPRã«åºã¥ããŠãªããŒã¹ããå ŽåãäŸå€èŠæ±ã¯å¿ èŠãããŸããã PRã¯ã³ãŒããå®äºããç· ãåãã®1æ¥åã«æ¿èªãããŸããã
ããã«ã¡ã¯@liggitt ïŒwave ïŒããå ¥åããããšãããããŸãã ïŒ+1ïŒ
æ¡åŒµæ©èœããµã€ã¯ã«ã«æ»ããŸãã ç§ãã¡ã®ãã¹ãŠã®æžå¿µã¯ãªããŒã¹ã«é¢ãããã®ã§ããã ããã¯ãœãŒããããŠããã®ã§ãããã¯è¯ãããšã§ãã ïŒslightly_smiling_faceïŒ
/ãã€ã«ã¹ããŒã³v1.19
@pjbgf @ saschagrunert @ hasheddan-ãã¹ãŠã®è²¢ç®ã«æè¬ããŸãã ïŒ100ïŒ
æ¡åŒµæ©èœã®è©³çŽ°ãªè¿œè·¡ãããŠããã@palnabarunã«æè¬ããŸãã æè¬ããŸãïŒ ð
@saschagrunertæçµçãªPRkubernetes / kubernetesïŒ92856ãã€ãã«ããŒãžãããŸãã ããã§ãšãããããŸãïŒ ãããåæ ããããã«ãã©ããã³ã°ã·ãŒããæŽæ°ããŸãã
@tallclair @pjbgf seccompã¯GAãªã®ã§ããã®åé¡ãä»ãã解決ã§ãããšæããŸããïŒ
@saschagrunertéåžžããªãªãŒã¹ãè¡ãããã®ãåŸ
ã£ãŠããã察å¿ããKEPãimplemented
ãšããŠããŒã¯ããŠãããæ¡åŒµæ©èœã®åé¡ãéããŸãã
https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/20190717-seccomp-ga.mdãimplemented
ãšããŠããŒã¯ããããã«ãèªç±ã«å€æŽãå ããŠãã ããã ïŒslightly_smiling_faceïŒ
@saschagrunertéåžžããªãªãŒã¹ãè¡ãããã®ãåŸ ã£ãŠããã察å¿ããKEPã
implemented
ãšããŠããŒã¯ããŠãããæ¡åŒµæ©èœã®åé¡ãéããŸããhttps://github.com/kubernetes/enhancements/blob/master/keps/sig-node/20190717-seccomp-ga.mdã
implemented
ãšããŠããŒã¯ããããã«ãèªç±ã«å€æŽãå ããŠãã ããã
説æãããããšãã httpsïŒ//github.com/kubernetes/enhancements/pull/1932ã§PRãéããŸãã
KEPãæŽæ°ãããŠå®è£ ãããŸããïŒPRãã€ãã«çµ±åãããŸããïŒïŒ
ãã®åé¡ã@saschagrunertã§ãæ°è»œã«éããŠãã ãã
ã¿ãªãããããããšãããããŸãã!!
/ãã€ã«ã¹ããŒã³ã¯ãªã¢
/éžã¶
ããã§å®äºã§ãã
@saschagrunert以åã«ããã«ã€ããŠè©±ãåã£ããã©ããã¯æãåºããŸããããæçµçã«ã¢ãããŒã·ã§ã³ãã¯ãªãŒã³ã¢ããããïŒã€ãŸãããµããŒããåé€ããïŒèšç»ã¯ãããŸããïŒ ããããäž»ãªåæ©ã¯ããµãŒãããŒãã£ã®ããŒã«ïŒã²ãŒãããŒããŒãkrailãªã©ïŒã泚éãšãã£ãŒã«ãã®äž¡æ¹ããã§ãã¯ããããšãç¥ãå¿ èŠããªãããã«ããããšã§ãã
@saschagrunert以åã«ããã«ã€ããŠè©±ãåã£ããã©ããã¯æãåºããŸããããæçµçã«ã¢ãããŒã·ã§ã³ãã¯ãªãŒã³ã¢ããããïŒã€ãŸãããµããŒããåé€ããïŒèšç»ã¯ãããŸããïŒ ããããäž»ãªåæ©ã¯ããµãŒãããŒãã£ã®ããŒã«ïŒã²ãŒãããŒããŒãkrailãªã©ïŒã泚éãšãã£ãŒã«ãã®äž¡æ¹ããã§ãã¯ããããšãç¥ãå¿ èŠããªãããã«ããããšã§ãã
ã¯ããããã¯v1.23ã§èšç»ãããŠããŸãã ããã«ã¯ãå¿ èŠãªãŠãŒãã£ãªãã£æ©èœãååšããåŸã«å®è¡ã§ããèŠåã¡ã«ããºã ïŒãŸã å®è¡ãããŠããŸããïŒãçµã¿èŸŒãŸããŠããŸãïŒhttps://github.com/kubernetes/kubernetes/issues/94626ãåç §ïŒã
KEPããïŒ
泚éã®äœ¿çšæ³ã®èªèãé«ããããã«ïŒå€ãèªååã®å ŽåïŒãèŠåã¡ã«ããºã ã䜿çšããŠãv1.23ã§ãµããŒããå»æ¢ãããããšã匷調ããŸãã æ€èšãããŠããã¡ã«ããºã ã¯ãKEPïŒ1693ã§èª¬æãããŠããããã«ãç£æ»ã¢ãããŒã·ã§ã³ããªããžã§ã¯ãã®ã¢ãããŒã·ã§ã³ãã€ãã³ãããŸãã¯èŠåã§ãã
âŠ
ãã¹ã¿ãŒãšããŒãéã®ããŒãžã§ã³ã¹ãã¥ãŒã®æ倧2ã€ã®ãã€ããŒãªãªãŒã¹ããµããŒãããŠãããããæåã®å®è£ ã«åæ Œããå°ãªããšã2ã€ã®ããŒãžã§ã³ã«ã€ããŠãã¢ãããŒã·ã§ã³ãåŒãç¶ããµããŒãããåãæ»ãå¿ èŠããããŸãã ãã ããç Žæãæžããããã«ããµããŒããããã«æ¡åŒµããããšã決å®ã§ããŸãã ãã®æ©èœãv1.19ã§å®è£ ãããŠããå Žåãå€ãåäœãåé€ããããã®ã¿ãŒã²ãããšããŠv1.23ãææ¡ããŸãã
ãããã®ããããå®è£ ããããŸã§ããã®åé¡ãåéããŸããïŒ
ãããæ©èœãå®å šã«çµäºãããŸã§ãããéãããŸãŸã«ããŠãããŸãããã ããªãã説æããä»äºã«å¯ŸããŠæåºãããak / kã®åé¡ã¯ãããŸããïŒ
ãããæ©èœãå®å šã«çµäºãããŸã§ãããéãããŸãŸã«ããŠãããŸãããã ããªãã説æããä»äºã«å¯ŸããŠæåºãããak / kã®åé¡ã¯ãããŸããïŒ
ããã§1ã€ã«ãªããŸããïŒhttpsïŒ//github.com/kubernetes/kubernetes/issues/95171 :)
æãåèã«ãªãã³ã¡ã³ã
Dockerã®dockerããã©ã«ããããã¡ã€ã«ãèµ·åãããšãã«ã