Exclude kubelet daemon is running in unconfined_t
Issue
- The
rhcos4-selinux-confinement-of-daemonsrule has been disabled in4.12.26release which means that any daemon could be running inunconfined_tand we would not fail a compliance check for it. - For user this is not an operational issue, but more of a security concern that this rule has been fully disabled and not fixed to allow for
kubeletto run inunconfined_t.
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4.12.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.