Skip to content

linkerd-init violates the baseline Pod Security Standard #11097

Answered by alpeb
MarkKharitonov asked this question in General
Discussion options

You must be logged in to vote

That's right, unfortunately, linkerd-init is incompatible with a anything but a privileged PSS, given that mechanism's coarse grained policies. If you're required to enforce a more restrictive PSS policy you can via the linkerd-cni model, which refrains from using the linkerd-init container for setting up the iptable rules required by the proxy.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Answer selected by MarkKharitonov
Comment options

You must be logged in to vote
1 reply
@alpeb
Comment options

alpeb Jul 10, 2023
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants