podsec - a set of scripts for deploying and supporting secure rootless solutions for podman and rootless-kubernetes (podsec-u7s) within the c10+, p10+ ALTLinux distributions.
Provides:
-
Deploying a
rootfullorrootlesskubernetescluster versionv1.26.3and higher -
Creating users of different categories with different rights to access and work with docker images.
-
Creation of an image
docker registryand aWEB server for access to image signatures. -
Setting up access policies and working with images for several categories of users.
-
Providing users access to the kubernetes cluster.
-
Configuring RBAC access rules to the kubernetes cluster.
For step by step migration from rootfull clusters it is possible to deploy heterogeneous clusters by connecting rootless nodes to a rootfull cluster.
In this case, there is no need to use the other features (2-6).
Installation and configuration details are described on the Rootless kubernetes page.
Users are divided into the following categories:
-
Administrators - users belonging to the
whellgroup including root. -
The
rootless kubernetesadministrator isu7s-admin. -
Creators of
docker images -
Users of
docker images
This user category has the right to create creator users and docker image users.
In addition, when creating a kubernetes cluster, they have the right to administer the cluster.
This user belongs to system users.
Not belong to the wheel group. From the point of view of the host system, he is an ordinary (non-privileged) user.
All Pods in the rootless kubernetes cluster are launched on his behalf (under his uid) and within his namespace.
Like the Administrator, he has the right to administer the rootless kubernetes cluster.
But unlike it, it allows you to enter its namespace and administer the resources of this namespace within the node:
- network interfaces
tap0,cni0, ...; iptablesrules;- files and directories created within this
namespace; - processes;
- ...
In addition, it allows you to view the logs of the node's Pods in the directory /var/log/pods/...
Users in this category have all rights to work with images:
-
Download images from any available registrar.
-
Import/Export of images from archive formats.
-
Creating images from
Dockefile's. -
Placing images on recorders.
-
Placing your images with your electronic signature on the local registrar
registry.local
Users belong to the groups podman-dev, podman.
Users in this category do not have any of the above rights to work with images, with the exception of downloading signed images from the local registry registry.local and working with them.
Users belong to podman groups.
The specification file podsec.spec provides the creation of the following RPM packages:
-
podsec- a set of scripts for creatingusers,access policies, deploying alocal registry andWEB signature server, loading an archive of kubernetes images into thelocal registry`. -
podsec-k8s- a set of scripts for deploying a rootlesskubernetescluster -
podsec-k8s-rbac- a set of scripts for providing users with access to thekubernetes clusterand assigning them roles within the cluster. -
podsec-inotify- a set of scripts for monitoring violations of security policies. -
podsec-dev- a set of scripts for installing and updatingkubernetes images.
podsec*packages work underLinux kernelversion5.15and higher.