Hi!
Currently, StackRox policies do not apply allowPrivilegeEscalation checks to init/ephemeral containers.
We request support for this setting to ensure privilege escalation restrictions are enforced consistently across all container types.
Use Case:
I'm testing default policy Container with privilege escalation allowed using manifest below and there is no violation:
apiVersion: v1
kind: Pod
metadata:
name: init-container-privilege-test
spec:
initContainers:
- name: init-test-container
image: busybox
command: ["sh", "-c", "echo Init container"]
securityContext:
allowPrivilegeEscalation: true
containers:
- name: main-container
image: nginx
securityContext:
allowPrivilegeEscalation: false
Hi!
Currently, StackRox policies do not apply
allowPrivilegeEscalationchecks to init/ephemeral containers.We request support for this setting to ensure privilege escalation restrictions are enforced consistently across all container types.
Use Case:
I'm testing default policy
Container with privilege escalation allowedusing manifest below and there is no violation: