SeccompProfile
kguardian.dev / v1alpha1
apiVersion: kguardian.dev/v1alpha1
kind: SeccompProfile
metadata:
name: example
spec object required
Spec of a `SeccompProfile`: a seccomp profile in its native shape,
plus an optional pointer at the workload it is for.
architectures
[]string
Architectures the profile applies to (seccomp `architectures`).
Omitted ⇒ the rendered file carries no `architectures` field.
defaultAction
string required
Action for any syscall not matched by a rule.
enum:
SCMP_ACT_LOG, SCMP_ACT_ERRNO, SCMP_ACT_KILL, SCMP_ACT_KILL_PROCESSsyscalls []object required
Syscall rules. kguardian generates `SCMP_ACT_ALLOW` rules only;
the other actions are accepted for hand edits.
minItems:
1
action
string required
enum:
SCMP_ACT_ALLOW, SCMP_ACT_LOG, SCMP_ACT_ERRNO, SCMP_ACT_KILL, SCMP_ACT_KILL_PROCESS
errnoRet
integer
errno to return for `SCMP_ACT_ERRNO` rules.
format:
uint32minimum:
0
names
[]string required
Syscall names (`^[a-z][a-z0-9_]{0,63}$`).
minItems:
1workloadRef object
The workload this profile is for. Enables the `CaptureComplete`
and `Drift` conditions; optional.
kind
string required
enum:
Deployment, StatefulSet, DaemonSet, CronJob, Job, ReplicaSet, ReplicationController
name
string required
status object
`status` of a `SeccompProfile`. Two writers: each controller
server-side-applies its own `nodes[name=<node>]` entry (field manager
`kguardian-controller/<node>`), and every controller applies the same
computed summary (everything else) under the shared manager
`kguardian-summary`, so the summary converges to the last writer.
conditions []object
lastTransitionTime
string
message
string
reason
string required
status
string required
`"True"`, `"False"` or `"Unknown"`.
type
string required
denials object
Seccomp denials the broker has attributed to this CR's workload:
syscalls the kernel's own filter acted on, as opposed to `drift`,
which is inferred from what kguardian observed the workload call.
A settled reading, not a live counter, and `refreshedAt` says when it
was taken. Every node polls the Broker on its own schedule, so every
node holds a slightly different reading; writing each one back would
have the fleet rewrite this CR without end. A node therefore
republishes the block only when its own reading is strictly stronger
than the published one — a syscall or a verdict not listed there, or
an order of magnitude more events — and otherwise leaves it alone
until it is more than 15 minutes old, at which point the next node to
reconcile replaces it outright.
So `observed` trails live activity by up to 15 minutes, and it trails
it in one direction: a workload climbing from 1,200 to 9,900 inside
one order of magnitude keeps reporting 1,200 until the refresh, and
so does a count that falls, whether because the retention window
pruned older events or because the workload stopped. Read it as
"denials on this scale, as of `refreshedAt`", not as a total. `GET
/seccomp/denials` on the Broker is the live, per-event view.
Present whenever the Broker gave an answer, including when that
answer is zero. `observed: 0` means "checked, and clean". The whole
block being absent means "not known" — the Broker was unreachable, it
predates denial capture, or nothing on this cluster is capturing
denials at all.
Keeping those two apart is the point of the field. Zero is what
clears a profile for promotion from `SCMP_ACT_LOG` to an enforcing
action; absent is no evidence whatsoever, and collapsing them would
hand out that clearance on the strength of nobody having looked. The
`Denials` printer column reads `observed` straight out of this block,
so it shows `0` for a cleared workload and stays blank for an unknown
one — readable without going and fetching the condition. The
`DenialsObserved` condition carries the same distinction with a
reason attached, and its message renders this block and nothing else,
so `kubectl get` and `kubectl describe` cannot name two different
numbers.
actions
[]string
The `SCMP_ACT_*` verdicts the kernel returned in this reading,
sorted. What separates a profile that is only logging from one
that is returning errors to the workload or killing it.
lastSeen
string
RFC 3339; the most recent denial in this reading, when there has
been one.
observed
integer required
Denial events in this reading, across every syscall and action.
This is the `Denials` printer column. Up to 15 minutes behind the
Broker, and coarse — see the note on this block.
format:
uint64minimum:
0
refreshedAt
string
RFC 3339; when this reading was taken from the Broker. Every
other field in the block is as of this instant. Absent on a block
written by a controller from before this field existed; the next
reconcile stamps one.
syscalls
[]string
Distinct syscall names denied in this reading, sorted.
distribution object
ready
integer required
format:
uint32minimum:
0
state
string required
enum:
Ready, Partial, Pending
summary
string
`ready/total`, for the `Ready` printer column.
total
integer required
format:
uint32minimum:
0
drift
string
Mirror of the `Drift` condition's status (`True`/`False`/`Unknown`)
for the printer column — CRD printer columns take simple JSON
paths only, no `[?(@.type=="Drift")]` filters.
hash
string
FNV-1a-64 (hex) of the rendered file — what is on a ready node.
localhostProfile
string
The `localhostProfile` value pods reference.
nodes []object
Per-node state; each entry is owned by that node's controller.
hash
string required
lastWritten
string
RFC 3339; when this node last wrote the file.
name
string required
observedGeneration
integer
format:
int64No matches. Try .spec.architectures for an exact path