numerous-country-20400
10/18/2022, 8:58 PMforbidden seccomp may not be set
- for example the new cert-manager 1.10 introduces https://artifacthub.io/packages/helm/cert-manager/cert-manager/1.10.0#default-security-contexts a new default security context - thus i cannot install it on my rke2 cluster. Same goes with bitnami-wordpress start 15.2.0 which also introduce RuntimeDefault as their default runtime. Is there anything missing in my rke2 configuration or do i miss the point entirely?creamy-pencil-82913
10/18/2022, 9:21 PMnumerous-country-20400
10/18/2022, 9:23 PMcurl -sfL <https://get.rke2.io> | sh -
with a fairly simple default config https://gist.github.com/EugenMayer/cdf7ac12b02280fcd1fa885018994568kubectl get psp -A
i see global-restricted-psp
and global-unrestricted-psp
- i guess when cert-manager 1.10 is installed and using RuntimeDefault
as the default, the the PSP is switched to global-restricted-psp
right. And something in there is not allowedcreamy-pencil-82913
10/18/2022, 9:38 PMnumerous-country-20400
10/18/2022, 9:46 PM<http://seccomp.security.alpha.kubernetes.io/allowedProfileNames|seccomp.security.alpha.kubernetes.io/allowedProfileNames>: '*'
somewhat means, what profiles can be used (like "RuntimeDefault") ?creamy-pencil-82913
10/18/2022, 9:49 PMnumerous-country-20400
10/18/2022, 9:52 PMcreamy-pencil-82913
10/18/2022, 9:53 PMnumerous-country-20400
10/18/2022, 9:54 PMcreamy-pencil-82913
10/18/2022, 9:54 PMnumerous-country-20400
10/18/2022, 9:55 PMcreamy-pencil-82913
10/18/2022, 9:56 PMnumerous-country-20400
10/18/2022, 9:56 PMcreamy-pencil-82913
10/18/2022, 9:57 PMhelm install
and it comes back with an error where?numerous-country-20400
10/18/2022, 9:57 PMcreamy-pencil-82913
10/18/2022, 9:57 PMnumerous-country-20400
10/18/2022, 9:57 PMcreamy-pencil-82913
10/18/2022, 9:58 PMnumerous-country-20400
10/18/2022, 9:58 PMcreamy-pencil-82913
10/18/2022, 9:58 PMnumerous-country-20400
10/18/2022, 10:00 PM<http://seccomp.security.alpha.kubernetes.io/allowedProfileNames|seccomp.security.alpha.kubernetes.io/allowedProfileNames>: "*"
to the global unrestricted PSP, it does deploy just finecreamy-pencil-82913
10/18/2022, 10:01 PMnumerous-country-20400
10/18/2022, 10:01 PMcreamy-pencil-82913
10/18/2022, 10:03 PMnumerous-country-20400
10/18/2022, 10:04 PMcreamy-pencil-82913
10/18/2022, 10:40 PMnumerous-country-20400
10/18/2022, 10:42 PM