Skip to content

Feature Request: Add support for allowPrivilegeEscalation check in init/ephemeral containers #13133

Description

@GurbanV

Hi!

Currently, StackRox policies do not apply allowPrivilegeEscalation checks to init/ephemeral containers.

We request support for this setting to ensure privilege escalation restrictions are enforced consistently across all container types.

Use Case:
I'm testing default policy Container with privilege escalation allowed using manifest below and there is no violation:

apiVersion: v1
kind: Pod
metadata:
  name: init-container-privilege-test
spec:
  initContainers:
    - name: init-test-container
      image: busybox
      command: ["sh", "-c", "echo Init container"]
      securityContext:
        allowPrivilegeEscalation: true
  containers:
    - name: main-container
      image: nginx
      securityContext:
        allowPrivilegeEscalation: false

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions