Run as non-root

I tried to follow a principle of encapsulation here - we can still default to
peeps making connections to 80/443 on a Service object, but internally we will
use 8080/8443.

Signed-off-by: Andrew Keesler <akeesler@vmware.com>
This commit is contained in:
Andrew Keesler
2020-11-02 12:51:15 -05:00
parent 7639d5e161
commit fcea48c8f9
14 changed files with 54 additions and 41 deletions
+6 -3
View File
@@ -86,6 +86,9 @@ spec:
annotations:
scheduler.alpha.kubernetes.io/critical-pod: ""
spec:
securityContext:
runAsUser: 1001
runAsGroup: 1001
serviceAccountName: #@ defaultResourceName()
#@ if data.values.image_pull_dockerconfigjson and data.values.image_pull_dockerconfigjson != "":
imagePullSecrets:
@@ -113,7 +116,7 @@ spec:
livenessProbe:
httpGet:
path: /healthz
port: 443
port: 8443
scheme: HTTPS
initialDelaySeconds: 2
timeoutSeconds: 15
@@ -122,7 +125,7 @@ spec:
readinessProbe:
httpGet:
path: /healthz
port: 443
port: 8443
scheme: HTTPS
initialDelaySeconds: 2
timeoutSeconds: 3
@@ -173,7 +176,7 @@ spec:
ports:
- protocol: TCP
port: 443
targetPort: 443
targetPort: 8443
---
apiVersion: apiregistration.k8s.io/v1
kind: APIService
@@ -47,6 +47,9 @@ spec:
labels:
app: local-user-authenticator
spec:
securityContext:
runAsUser: 1001
runAsGroup: 1001
serviceAccountName: local-user-authenticator
#@ if data.values.image_pull_dockerconfigjson and data.values.image_pull_dockerconfigjson != "":
imagePullSecrets:
@@ -77,4 +80,4 @@ spec:
ports:
- protocol: TCP
port: 443
targetPort: 443
targetPort: 8443
+6 -6
View File
@@ -47,7 +47,7 @@ The most common ways are:
1. Define an [`Ingress` resource](https://kubernetes.io/docs/concepts/services-networking/ingress/) with TLS certificates.
In this case, the ingress will terminate TLS. Typically, the ingress will then talk plain HTTP to its backend,
which would be a NodePort or LoadBalancer Service in front of the HTTP port 80 of the Supervisor pods.
which would be a NodePort or LoadBalancer Service in front of the HTTP port 8080 of the Supervisor pods.
The required configuration of the Ingress is specific to your cluster's Ingress Controller, so please refer to the
documentation from your Kubernetes provider. If you are using a cluster from a cloud provider, then you'll probably
@@ -60,10 +60,10 @@ The most common ways are:
1. Or, define a [TCP LoadBalancer Service](https://kubernetes.io/docs/concepts/services-networking/service/#loadbalancer)
which is a layer 4 load balancer and does not terminate TLS. In this case, the Supervisor app will need to be
configured with TLS certificates and will terminate the TLS connection itself (see the section about
OIDCProviderConfig below). The LoadBalancer Service should be configured to use the HTTPS port 443 of
OIDCProviderConfig below). The LoadBalancer Service should be configured to use the HTTPS port 8443 of
the Supervisor pods as its `targetPort`.
*Warning:* Do not expose the Supervisor's port 80 to the public. It would not be secure for the OIDC protocol
*Warning:* Do not expose the Supervisor's port 8080 to the public. It would not be secure for the OIDC protocol
to use HTTP, because the user's secret OIDC tokens would be transmitted across the network without encryption.
1. Or, expose the Supervisor app using a Kubernetes service mesh technology, e.g. [Istio](https://istio.io/).
@@ -79,7 +79,7 @@ so if you choose to use an Ingress then you'll need to create that separately af
#### Example: Using a LoadBalancer Service
This is an example of creating a LoadBalancer Service to expose port 443 of the Supervisor app outside the cluster.
This is an example of creating a LoadBalancer Service to expose port 8443 of the Supervisor app outside the cluster.
```yaml
apiVersion: v1
@@ -96,7 +96,7 @@ spec:
ports:
- protocol: TCP
port: 443
targetPort: 443
targetPort: 8443
```
#### Example: Using a NodePort Service
@@ -127,7 +127,7 @@ spec:
ports:
- protocol: TCP
port: 80
targetPort: 80
targetPort: 8080
nodePort: 31234 # This is the port that you would forward to the kind host. Or omit this key for a random port.
```
+7 -4
View File
@@ -60,6 +60,9 @@ spec:
metadata:
labels: #@ defaultLabel()
spec:
securityContext:
runAsUser: 1001
runAsGroup: 1001
serviceAccountName: #@ defaultResourceName()
#@ if data.values.image_pull_dockerconfigjson and data.values.image_pull_dockerconfigjson != "":
imagePullSecrets:
@@ -87,14 +90,14 @@ spec:
- name: podinfo
mountPath: /etc/podinfo
ports:
- containerPort: 80
- containerPort: 8080
protocol: TCP
- containerPort: 443
- containerPort: 8443
protocol: TCP
livenessProbe:
httpGet:
path: /healthz
port: 80
port: 8080
scheme: HTTP
initialDelaySeconds: 2
timeoutSeconds: 15
@@ -103,7 +106,7 @@ spec:
readinessProbe:
httpGet:
path: /healthz
port: 80
port: 8080
scheme: HTTP
initialDelaySeconds: 2
timeoutSeconds: 3
+6 -6
View File
@@ -21,7 +21,7 @@ spec:
- name: http
protocol: TCP
port: #@ data.values.service_http_nodeport_port
targetPort: 80
targetPort: 8080
#@ if data.values.service_http_nodeport_nodeport:
nodePort: #@ data.values.service_http_nodeport_nodeport
#@ end
@@ -30,7 +30,7 @@ spec:
- name: https
protocol: TCP
port: #@ data.values.service_https_nodeport_port
targetPort: 443
targetPort: 8443
#@ if data.values.service_https_nodeport_nodeport:
nodePort: #@ data.values.service_https_nodeport_nodeport
#@ end
@@ -53,13 +53,13 @@ spec:
- name: http
protocol: TCP
port: #@ data.values.service_http_clusterip_port
targetPort: 80
targetPort: 8080
#@ end
#@ if data.values.service_https_clusterip_port:
- name: https
protocol: TCP
port: #@ data.values.service_https_clusterip_port
targetPort: 443
targetPort: 8443
#@ end
#@ end
@@ -82,12 +82,12 @@ spec:
- name: http
protocol: TCP
port: #@ data.values.service_http_loadbalancer_port
targetPort: 80
targetPort: 8080
#@ end
#@ if data.values.service_https_loadbalancer_port:
- name: https
protocol: TCP
port: #@ data.values.service_https_loadbalancer_port
targetPort: 443
targetPort: 8443
#@ end
#@ end
+6 -6
View File
@@ -40,14 +40,14 @@ image_pull_dockerconfigjson: #! e.g. {"auths":{"https://registry.example.com":{"
#! An HTTP service should not be exposed outside the cluster. It would not be secure to serve OIDC endpoints to end users via HTTP.
#! Setting any of these values means that a Service of that type will be created.
#! Note that all port numbers should be numbers (not strings), i.e. use ytt's `--data-value-yaml` instead of `--data-value`.
service_http_nodeport_port: #! when specified, creates a NodePort Service with this `port` value, with port 80 as its `targetPort`; e.g. 31234
service_http_nodeport_port: #! when specified, creates a NodePort Service with this `port` value, with port 8080 as its `targetPort`; e.g. 31234
service_http_nodeport_nodeport: #! the `nodePort` value of the NodePort Service, optional when `service_http_nodeport_port` is specified; e.g. 31234
service_http_loadbalancer_port: #! when specified, creates a LoadBalancer Service with this `port` value, with port 80 as its `targetPort`; e.g. 443
service_http_clusterip_port: #! when specified, creates a ClusterIP Service with this `port` value, with port 80 as its `targetPort`; e.g. 443
service_https_nodeport_port: #! when specified, creates a NodePort Service with this `port` value, with port 443 as its `targetPort`; e.g. 31243
service_http_loadbalancer_port: #! when specified, creates a LoadBalancer Service with this `port` value, with port 8080 as its `targetPort`; e.g. 8443
service_http_clusterip_port: #! when specified, creates a ClusterIP Service with this `port` value, with port 8080 as its `targetPort`; e.g. 8443
service_https_nodeport_port: #! when specified, creates a NodePort Service with this `port` value, with port 8443 as its `targetPort`; e.g. 31243
service_https_nodeport_nodeport: #! the `nodePort` value of the NodePort Service, optional when `service_http_nodeport_port` is specified; e.g. 31243
service_https_loadbalancer_port: #! when specified, creates a LoadBalancer Service with this `port` value, with port 443 as its `targetPort`; e.g. 443
service_https_clusterip_port: #! when specified, creates a ClusterIP Service with this `port` value, with port 443 as its `targetPort`; e.g. 443
service_https_loadbalancer_port: #! when specified, creates a LoadBalancer Service with this `port` value, with port 8443 as its `targetPort`; e.g. 8443
service_https_clusterip_port: #! when specified, creates a ClusterIP Service with this `port` value, with port 8443 as its `targetPort`; e.g. 8443
#! The `loadBalancerIP` value of the LoadBalancer Service.
#! Ignored unless service_http_loadbalancer_port and/or service_https_loadbalancer_port are provided.
#! Optional.