Managed Kubernetes
Latest
Frequently Asked Questions
Solutions
How Tos
Internal Only
Templates
Powered By

Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Reduce The Number Of Privilege Escalations Using Sudo While Executing PF9 Scripts/Commands In The Workload Nodes.
Copy Markdown
Open in ChatGPT
Open in Claude
Problem
In environments where LDAP is configured, it is observed that every command that runs as part of the Nodeletd phases requires a sudo privilege. This is is resulting in high number of ldap lookups even though pf9user is a local user.
PF9 scripts using sudo
xxxxxxxxxxOct 11 12:00:43 : pf9 : HOST=XXXXXXXXXX : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/opt/pf9/pf9-kube/setup_env_and_run_script.sh /opt/pf9/pf9-kube/phases/kubelet_configure_start.sh statusOct 11 12:00:43 : pf9 : HOST=XXXXXXXXXX : TTY=unknown ; PWD=/ ; USER=root ; COMMAND=/opt/pf9/pf9-kube/setup_env_and_run_script.sh /opt/pf9/pf9-kube/phases/kube_proxy_start.sh statusEnvironment
- Platform9 Managed Kubernetes - v5.5 and Higher.
Answer
This issue is resolved in PMK-5.10.3 release version. The JIRA to track this issue is [PMK-6173].
VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches
Last updated on
Was this page helpful?
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message