Skip to content
This repository has been archived by the owner on Feb 22, 2022. It is now read-only.

[stable/datadog] Add some missing syscalls to the system-probe seccomp profile #21456

Merged
merged 1 commit into from
Mar 17, 2020

Conversation

L3n41c
Copy link
Collaborator

@L3n41c L3n41c commented Mar 13, 2020

What this PR does / why we need it:

Add some missing syscalls to the system-probe seccomp profile

Which issue this PR fixes

There’s some OS / kernel versions where system-probe ends in CrashLoopBackOff state with the current seccomp profile. And reverting to the default seccomp profile fixes the issue, which is the sign that the current seccomp profile is too restrictive of those platforms.

So, I ran system-probe under strace with the default seccomp profile to see all the syscalls that it does and I added in the custom seccomp profile the ones that were missing.

Special notes for your reviewer:

Checklist

[Place an '[x]' (no spaces) in all applicable fields. Please remove unrelated fields.]

  • DCO signed
  • Chart Version bumped
  • Variables are documented in the README.md
  • Title of the PR starts with chart name (e.g. [stable/mychartname])

@helm-bot helm-bot added Contribution Allowed If the contributor has signed the DCO or the CNCF CLA (prior to the move to a DCO). size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Mar 13, 2020
@k8s-ci-robot k8s-ci-robot added approved Indicates a PR has been approved by an approver from all required OWNERS files. needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Mar 13, 2020
@k8s-ci-robot
Copy link
Contributor

Hi @L3n41c. Thanks for your PR.

I'm waiting for a helm member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@clamoriniere
Copy link
Collaborator

/ok-to-test
Hi @L3n41c, could you please rebase this PR.

@k8s-ci-robot k8s-ci-robot added ok-to-test and removed needs-ok-to-test Indicates a PR that requires an org member to verify it is safe to test. labels Mar 15, 2020
@L3n41c
Copy link
Collaborator Author

L3n41c commented Mar 16, 2020

Hi @clamoriniere ,
This PR has just been rebased.

…omp profile

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
@helm-bot helm-bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Mar 17, 2020
@clamoriniere
Copy link
Collaborator

/ok-to-test

@clamoriniere
Copy link
Collaborator

/lgtm

@k8s-ci-robot k8s-ci-robot added the lgtm Indicates that a PR is ready to be merged. label Mar 17, 2020
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: clamoriniere, L3n41c

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot merged commit 017b3c0 into helm:master Mar 17, 2020
@L3n41c L3n41c deleted the seccomp branch March 18, 2020 08:06
omerli pushed a commit to omerli/charts that referenced this pull request Mar 19, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>
k8s-ci-robot pushed a commit that referenced this pull request Mar 19, 2020
…template (#21510)

* enable deployment annotations, bump chart version (#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
fowlie pushed a commit to fowlie/charts that referenced this pull request Mar 20, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
fowlie pushed a commit to fowlie/charts that referenced this pull request Mar 20, 2020
…template (helm#21510)

* enable deployment annotations, bump chart version (helm#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (helm#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (helm#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (helm#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
irlevesque pushed a commit to quantopian/charts that referenced this pull request Jul 13, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
irlevesque pushed a commit to quantopian/charts that referenced this pull request Jul 13, 2020
…template (helm#21510)

* enable deployment annotations, bump chart version (helm#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (helm#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (helm#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (helm#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
includerandom pushed a commit to includerandom/helm_charts that referenced this pull request Jul 19, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
includerandom pushed a commit to includerandom/helm_charts that referenced this pull request Jul 19, 2020
…template (helm#21510)

* enable deployment annotations, bump chart version (helm#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (helm#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (helm#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (helm#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
li-adrienloiseau pushed a commit to li-adrienloiseau/charts that referenced this pull request Jul 29, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Adrien Loiseau <adrien.loiseau@logic-immo.com>
li-adrienloiseau pushed a commit to li-adrienloiseau/charts that referenced this pull request Jul 29, 2020
…template (helm#21510)

* enable deployment annotations, bump chart version (helm#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (helm#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (helm#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (helm#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
Signed-off-by: Adrien Loiseau <adrien.loiseau@logic-immo.com>
mmingorance-dh pushed a commit to mmingorance-dh/charts that referenced this pull request Aug 28, 2020
…omp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Miguel Mingorance <miguel.mingorance@deliveryhero.com>
mmingorance-dh pushed a commit to mmingorance-dh/charts that referenced this pull request Aug 28, 2020
…template (helm#21510)

* enable deployment annotations, bump chart version (helm#21502)

Signed-off-by: Ryan Holt <ryan@ryanholt.net>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datalog] Do not enable the `cri` check when running on a `docker` setup (helm#21476)

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/datadog] Add some missing syscalls to the `system-probe` seccomp profile (helm#21456)

The added syscalls are syscalls that an unconfined `system-probe` would do.

Signed-off-by: Lénaïc Huard <lenaic.huard@datadoghq.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/minio] corrected syntax error in statefulset (helm#21503)

* corrected syntax error in statefulset

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>

* chart version bump

Signed-off-by: Thomas Wilkinson <thomas.wilkinson@us.ibm.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* [stable/redis-ha] Make emptyDir configurable from values (helm#21489)

Signed-off-by: Jeroen Castelein <jeroencastelein11@gmail.com>
Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Set DD_APM_ENABLED

With the new Helm chart, even if `datadog.apm.enabled` is set to false, it reverts to the docker defaults (true). 
Having the trace-agent running in the background is pretty harmless from a resource overhead standpoint, however, the logic of the helm chart will automatically do the 8126 port-forwarding, and since we don't want non-apm customers to have this port exposed, we need to respect the chart settings.

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* Bumped version

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* 2.0.12

Fixed a bug where datadog.apm.enabled was not being respected

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

* re-applying the changes

Signed-off-by: Omer Lifshitz <omer.lifshitz@datadoghq.com>

Co-authored-by: Ryan Holt <ryan@ryanholt.net>
Co-authored-by: Lénaïc Huard <L3n41c@users.noreply.github.com>
Co-authored-by: Thomas Wilkinson <thomas@capnajax.com>
Co-authored-by: Jeroen Castelein <jeroen.castelein@kpn.com>
Signed-off-by: Miguel Mingorance <miguel.mingorance@deliveryhero.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
approved Indicates a PR has been approved by an approver from all required OWNERS files. Contribution Allowed If the contributor has signed the DCO or the CNCF CLA (prior to the move to a DCO). lgtm Indicates that a PR is ready to be merged. ok-to-test size/S Denotes a PR that changes 10-29 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants