Skip to content

[WIP] 🌱 Change crt permissions in KCP to 0600 #12648

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

sbueringer
Copy link
Member

Signed-off-by: Stefan Büringer [email protected]

What this PR does / why we need it:

Which issue(s) this PR fixes (optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when PR gets merged):
Fixes #

@k8s-ci-robot k8s-ci-robot added the do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. label Aug 19, 2025
@k8s-ci-robot
Copy link
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign enxebre for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@k8s-ci-robot k8s-ci-robot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. do-not-merge/needs-area PR is missing an area label size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. labels Aug 19, 2025
@sbueringer sbueringer added the area/provider/control-plane-kubeadm Issues or PRs related to KCP label Aug 19, 2025
@k8s-ci-robot k8s-ci-robot removed the do-not-merge/needs-area PR is missing an area label label Aug 19, 2025
@@ -393,7 +393,7 @@ func (c *Certificate) AsFiles() []bootstrapv1.File {
out = append(out, bootstrapv1.File{
Path: c.CertFile,
Owner: rootOwnerValue,
Permissions: "0640",
Permissions: "0600",
Copy link
Member Author

@sbueringer sbueringer Aug 19, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Context:

I wonder if 0600 leads to problems with: kubernetes/kubeadm#2473 (comment)

@neolit123 What do you think?

Is there a way that I can verify this works with userns? Do I only have to use Kubernetes >= 1.33?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if i understand how userns works, this might be fine. you can test with any new release that has userns support. i don't think we ever tested kubeadm with userns yet, fwiw.

they are still fixing bugs and updating docs for the feature and we need it to be ga.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also, cis has been annoying since it doesn't consider permissions of the parent dir. distributions on top of kubeadm and capi ca choose to generate their own certs, but that's extra work.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I was wondering if "userns is being enabled by default in 1.33" (kubernetes/kubeadm#2473 (comment)) means that it's also used for static Pods per default

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it's enabled in core k8s, but pod users must opt-in; kubeadm hasn't yet.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Got it, thx!

@sbueringer
Copy link
Member Author

/test pull-cluster-api-e2e-main

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/provider/control-plane-kubeadm Issues or PRs related to KCP cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. do-not-merge/work-in-progress Indicates that a PR should not merge because it is a work in progress. size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants