deploy/core: kubearmor for GKE latest COS images #648
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Detailed description:
GKE supports multiple images types, viz COS and non-COS(Ubuntu, Debian
etc). In case of non-COS images, the
/usr/src
contains the kernelheaders. In case of COS, kubearmor internally downloads the kernel
headers but still it used to mount
/usr/src
since we used a single yamlfor COS and non-COS images. In the latest releases of COS images
(for e.g., 1.22.6-gke-1000), the
/usr/src
folder is no longerpresent. The current changes now mounts /usr to /opt/hostusr folder for
GKE (only). The kubearmor code internally sets
BCC_KERNEL_SOURCE
to/media/root/usr/src/linux-headers-KERNELVER
.Fixes #579
Signed-off-by: Rahul Jadhav nyrahul@gmail.com