Skip to content

Conversation

hegerdes
Copy link

Why is this pull request needed and what does it do?

This adds an option which allows users to run coredns pod in usernamespaces. It increases security by separating the userids in the container from the one on the host.

This is a relative new feature and requires containerd >= 2.0 and kubernetes >= 1.30 (default enabled since 1.33). The flag is turned off by default and backwards compatible.

If you think this is to early to support this, just let me me know and we kann postpone this.

Which issues (if any) are related?

None yet

Checklist:

  • I have bumped the chart version according to versioning.
  • I have updated the chart changelog with all the changes that come with this pull request according to changelog.
  • Any new values are backwards compatible and/or have sensible default.
  • I have signed off all my commits as required by DCO.

Changes are automatically published when merged to main. They are not published on branches.

Note on DCO

If the DCO action in the integration test fails, one or more of your commits are not signed off. Please click on the Details link next to the DCO action for instructions on how to resolve this.

@hegerdes hegerdes force-pushed the feat/usernaemspaces branch from f4adc22 to a550e71 Compare May 29, 2025 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant