Skip to content

fix(uptime-kuma): drop NET_RAW so the pod passes baseline Pod Security - #78

Merged
PragalvaXFREZ merged 1 commit into
mainfrom
fix/uptime-kuma-baseline-psa
Sep 6, 2026
Merged

PragalvaXFREZ merged 1 commit into
mainfrom
fix/uptime-kuma-baseline-psa

Conversation

@PragalvaXFREZ

Copy link
Copy Markdown
Owner

What broke

After #73 synced, the ReplicaSet could not create a pod:

violates PodSecurity "baseline:latest": non-default capabilities (container "uptime-kuma" must not include "NET_RAW" in securityContext.capabilities.add)

Baseline permits only the Docker default capability set on add, and NET_RAW is not in it. The PVC, policy, and Service applied fine; only the pod was blocked.

Fix

  • Remove NET_RAW from securityContext.capabilities.add. All capabilities stay dropped.
  • Remove the ICMP egress rule from the CiliumNetworkPolicy, since nothing can use it now.
  • README: HTTP and TCP checks only; ping monitors listed as a known limitation with the reason.

Raising the namespace to privileged for a ping feature nobody asked for is the wrong trade. HTTP checks and the Discord webhook are the use case.

Validation

  • helm template render contains no NET_RAW.
  • kubeconform -strict and scripts/check-docs.py pass.

After merge

kubectl -n uptime get pod -o wide

The pod must reach Running on talos-lqv-w4u.

The baseline level forbids adding non-default capabilities, so the
ReplicaSet could not create a pod. Remove the capability and the ICMP
egress rule; ping monitors are documented as unsupported.

Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
@PragalvaXFREZ
PragalvaXFREZ merged commit 0251352 into main Sep 6, 2026
3 checks passed
@PragalvaXFREZ
PragalvaXFREZ deleted the fix/uptime-kuma-baseline-psa branch September 6, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant