Skip to search

SeccompProfile

kguardian.dev / v1alpha1

apiVersion: kguardian.dev/v1alpha1 kind: SeccompProfile metadata: name: example
View raw schema
spec object required
Spec of a `SeccompProfile`: a seccomp profile in its native shape, plus an optional pointer at the workload it is for.
architectures []string
Architectures the profile applies to (seccomp `architectures`). Omitted ⇒ the rendered file carries no `architectures` field.
defaultAction string required
Action for any syscall not matched by a rule.
enum: SCMP_ACT_LOG, SCMP_ACT_ERRNO, SCMP_ACT_KILL, SCMP_ACT_KILL_PROCESS
syscalls []object required
Syscall rules. kguardian generates `SCMP_ACT_ALLOW` rules only; the other actions are accepted for hand edits.
minItems: 1
action string required
enum: SCMP_ACT_ALLOW, SCMP_ACT_LOG, SCMP_ACT_ERRNO, SCMP_ACT_KILL, SCMP_ACT_KILL_PROCESS
errnoRet integer
errno to return for `SCMP_ACT_ERRNO` rules.
format: uint32
minimum: 0
names []string required
Syscall names (`^[a-z][a-z0-9_]{0,63}$`).
minItems: 1
workloadRef object
The workload this profile is for. Enables the `CaptureComplete` and `Drift` conditions; optional.
kind string required
enum: Deployment, StatefulSet, DaemonSet, CronJob, Job, ReplicaSet, ReplicationController
name string required
status object
`status` of a `SeccompProfile`. Two writers: each controller server-side-applies its own `nodes[name=<node>]` entry (field manager `kguardian-controller/<node>`), and every controller applies the same computed summary (everything else) under the shared manager `kguardian-summary`, so the summary converges to the last writer.
conditions []object
lastTransitionTime string
message string
reason string required
status string required
`"True"`, `"False"` or `"Unknown"`.
type string required
denials object
Seccomp denials the broker has attributed to this CR's workload: syscalls the kernel's own filter acted on, as opposed to `drift`, which is inferred from what kguardian observed the workload call. A settled reading, not a live counter, and `refreshedAt` says when it was taken. Every node polls the Broker on its own schedule, so every node holds a slightly different reading; writing each one back would have the fleet rewrite this CR without end. A node therefore republishes the block only when its own reading is strictly stronger than the published one — a syscall or a verdict not listed there, or an order of magnitude more events — and otherwise leaves it alone until it is more than 15 minutes old, at which point the next node to reconcile replaces it outright. So `observed` trails live activity by up to 15 minutes, and it trails it in one direction: a workload climbing from 1,200 to 9,900 inside one order of magnitude keeps reporting 1,200 until the refresh, and so does a count that falls, whether because the retention window pruned older events or because the workload stopped. Read it as "denials on this scale, as of `refreshedAt`", not as a total. `GET /seccomp/denials` on the Broker is the live, per-event view. Present whenever the Broker gave an answer, including when that answer is zero. `observed: 0` means "checked, and clean". The whole block being absent means "not known" — the Broker was unreachable, it predates denial capture, or nothing on this cluster is capturing denials at all. Keeping those two apart is the point of the field. Zero is what clears a profile for promotion from `SCMP_ACT_LOG` to an enforcing action; absent is no evidence whatsoever, and collapsing them would hand out that clearance on the strength of nobody having looked. The `Denials` printer column reads `observed` straight out of this block, so it shows `0` for a cleared workload and stays blank for an unknown one — readable without going and fetching the condition. The `DenialsObserved` condition carries the same distinction with a reason attached, and its message renders this block and nothing else, so `kubectl get` and `kubectl describe` cannot name two different numbers.
actions []string
The `SCMP_ACT_*` verdicts the kernel returned in this reading, sorted. What separates a profile that is only logging from one that is returning errors to the workload or killing it.
lastSeen string
RFC 3339; the most recent denial in this reading, when there has been one.
observed integer required
Denial events in this reading, across every syscall and action. This is the `Denials` printer column. Up to 15 minutes behind the Broker, and coarse — see the note on this block.
format: uint64
minimum: 0
refreshedAt string
RFC 3339; when this reading was taken from the Broker. Every other field in the block is as of this instant. Absent on a block written by a controller from before this field existed; the next reconcile stamps one.
syscalls []string
Distinct syscall names denied in this reading, sorted.
distribution object
ready integer required
format: uint32
minimum: 0
state string required
enum: Ready, Partial, Pending
summary string
`ready/total`, for the `Ready` printer column.
total integer required
format: uint32
minimum: 0
drift string
Mirror of the `Drift` condition's status (`True`/`False`/`Unknown`) for the printer column — CRD printer columns take simple JSON paths only, no `[?(@.type=="Drift")]` filters.
hash string
FNV-1a-64 (hex) of the rendered file — what is on a ready node.
localhostProfile string
The `localhostProfile` value pods reference.
nodes []object
Per-node state; each entry is owned by that node's controller.
hash string required
lastWritten string
RFC 3339; when this node last wrote the file.
name string required
observedGeneration integer
format: int64

No matches. Try .spec.architectures for an exact path