Skip to content

[PROF-15646] selinux annotation on install-seccomp - #3391

Draft
theomagellan wants to merge 1 commit into
mainfrom
theomagellan/initcontainer-selinux
Draft

[PROF-15646] selinux annotation on install-seccomp#3391
theomagellan wants to merge 1 commit into
mainfrom
theomagellan/initcontainer-selinux

Conversation

@theomagellan

@theomagellan theomagellan commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

What does this PR do?

On SELinux setups with containerd integration, /host/var/lib/kubelet/seccomp/ gets a var_lib_t label and denies operations to unprivileged containers.
On these setups, the host profiler's initcontainer fails as it was running under the default selinux profile.

Motivation

What inspired you to submit this pull request?

Additional Notes

Anything else we should know when reviewing?

Minimum Agent Versions

Are there minimum versions of the Datadog Agent and/or Cluster Agent required?

  • Agent: vX.Y.Z
  • Cluster Agent: vX.Y.Z

Describe your test plan

Write there any instructions and details you may have to test your PR.

Checklist

  • PR has at least one valid label: bug, enhancement, refactoring, documentation, tooling, and/or dependencies
  • PR has a milestone or the qa/skip-qa label
  • All commits are signed (see: signing commits)

@theomagellan theomagellan changed the title add selinux annotation to host profiler's install-seccomp init container [PROF-15646] selinux annotation on install-seccomp Aug 24, 2026
@theomagellan theomagellan added bug Something isn't working qa/skip-qa labels Aug 24, 2026
@datadog-datadog-us1-prod

Copy link
Copy Markdown

Code Coverage

🛑 Gate Violations

🎯 1 Code Coverage issue detected

A Patch coverage percentage gate may be blocking this PR.

Patch coverage: no data available (threshold: 80.00%)

ℹ️ Info

🎯 Code Coverage (details)
Patch Coverage: No data available
Overall Coverage: 50.13% (+0.00%)

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: a6a19ea | Docs | View more details | Give us feedback!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant