Urgent.News

What's breaking now, across thousands of outlets.

Tech

Seccomp profiles for real workloads, not for demos

Seccomp profiles for real workloads, not for demos A seccomp profile that denies everything except the calls a container needs is one of the strongest single controls in a Kubernetes cluster. Most clusters run the default RuntimeDefault profile, which is permissive, and a handful run custom profiles that were written for a demo and break the first real workload. The gap between those two states…

Seccomp profiles that limit container calls to just what a workload truly requires are critical, not just for demonstration purposes. Most Kubernetes clusters currently use the RuntimeDefault profile, which is overly permissive, while only a small number have custom profiles tailored for real-world use that fail when faced with actual workloads.

RuntimeDefault blocks the most common escape vectors, including filesystem mounts, kernel modules, and debugging interfaces, while permitting enough ordinary calls to support typical attacks. Custom profiles become necessary when the threat model involves the container itself, not just its boundary. Applications processing untrusted input in native code benefit from profiles that eliminate the exact exploit paths they rely on.

To build resilient profiles, start with the default settings and monitor the actual calls made during a full business cycle, including batch jobs, month-end processing, certificate rotation, and infrequent code paths. Version profiles alongside the application code and apply them in a non-enforcing mode first to catch any issues before fully enforcing them.

Seccomp restricts syscalls but does not address network, filesystem, or capability issues; it works best when combined with read-only root filesystems, dropped capabilities, and network policies.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 7 October →