Skip to content

atecontroller: add NET_BIND_SERVICE to gVisor worker capability set - #727

Open
Vinayak Somvanshi (VinayakSomvanshi) wants to merge 1 commit into
agent-substrate:mainfrom
VinayakSomvanshi:fix/ateom-net-bind-service
Open

atecontroller: add NET_BIND_SERVICE to gVisor worker capability set#727
Vinayak Somvanshi (VinayakSomvanshi) wants to merge 1 commit into
agent-substrate:mainfrom
VinayakSomvanshi:fix/ateom-net-bind-service

Conversation

@VinayakSomvanshi

Copy link
Copy Markdown

The ateom container uses Drop: ALL with an explicit Add list, so being UID 0 does not grant privileged-port binding — NET_BIND_SERVICE must be explicitly added. Without it, atunnel's listener on port 443 gets bind: permission denied on bare-metal nodes. GKE masked the bug via platform-level defaults that do not reliably propagate into every pod netns.

Tested on a bare-metal kubeadm cluster (RHEL 10.2, CRI-O 1.36.2).

  • Tests pass
  • Appropriate changes to documentation are included in the PR

The ateom container uses Drop: ALL with an explicit Add list, so being
UID 0 does not grant privileged-port binding — NET_BIND_SERVICE must be
explicitly added. Without it, atunnel's listener on port 443 gets
bind: permission denied on bare-metal nodes. GKE masked the bug via
platform-level defaults that do not reliably propagate into every pod
netns.

Tested on a bare-metal kubeadm cluster (RHEL 10, CRI-O 1.36).
@google-cla

google-cla Bot commented Aug 4, 2026

Copy link
Copy Markdown

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant