From dcbdb37902ea8e5679f6c561a99bf06e0ad7e031 Mon Sep 17 00:00:00 2001 From: Luke Kysow <1034429+lkysow@users.noreply.github.com> Date: Wed, 24 Jan 2024 21:50:48 +0000 Subject: [PATCH] backport of commit 9dd57ebe68cfe7f142ed106f0722775e1122ba45 --- .changelog/3498.txt | 3 +++ 1 file changed, 3 insertions(+) create mode 100644 .changelog/3498.txt diff --git a/.changelog/3498.txt b/.changelog/3498.txt new file mode 100644 index 0000000000..7aed5a69af --- /dev/null +++ b/.changelog/3498.txt @@ -0,0 +1,3 @@ +```release-note:improvement +cni: When CNI is enabled, set ReadOnlyRootFilesystem=true and AllowPrivilegeEscalation=false for mesh pod init containers and AllowPrivilegeEscalation=false for consul-dataplane containers (ReadOnlyRootFilesystem was already true for consul-dataplane containers). +```