Azure / AKS

Azure Kubernetes Service
https://azure.github.io/AKS/
1.96k stars 305 forks source link

[Feature] add support for bpf lsm to node group kernels #3574

Open learhy opened 1 year ago

learhy commented 1 year ago

In other managed Kubernetes distros bpf lsm support is enabled in newer kernels (> 5.10 usually). We were hoping to see this feature enabled on the latest node pools that come standard with aks 1.25 but it doesn't look to be the case:

AKSUbuntu-2204gen2containerd-2023.02.15

/etc # cat /sys/kernel/security/lsm
lockdown,capability,landlock,yama,AppArmor

We'd love to have feature parity on Azure as this is important to our customers-- can this feature be enabled?

learhy commented 1 year ago

Would love to know what the team thinks about this capability. Thanks.

alexeldeib commented 1 year ago

@justindavies we were talking about this I think? did we have an answer from LSG?

microsoft-github-policy-service[bot] commented 7 months ago

Action required from @Azure/aks-pm

microsoft-github-policy-service[bot] commented 7 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 6 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 6 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 5 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 5 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 4 months ago

Issue needing attention of @Azure/aks-leads

msecpim commented 4 months ago

Next to GKE and EKS, we would love to see this working for AKS as well. Is there any feedback as when that will be available for Azure customers?

microsoft-github-policy-service[bot] commented 4 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 2 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 2 months ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 month ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 month ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 3 weeks ago

Issue needing attention of @Azure/aks-leads

microsoft-github-policy-service[bot] commented 1 week ago

Issue needing attention of @Azure/aks-leads