Add KILL capability to CSPM container#2931
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2931 +/- ##
==========================================
+ Coverage 40.69% 40.86% +0.16%
==========================================
Files 321 324 +3
Lines 28413 29122 +709
==========================================
+ Hits 11563 11900 +337
- Misses 16015 16364 +349
- Partials 835 858 +23
Flags with carried forward coverage won't be shown. Click here to find out more.
... and 13 files with indirect coverage changes Continue to review full report in Codecov by Sentry.
🚀 New features to boost your workflow:
|
|
🎯 Code Coverage (details) 🔗 Commit SHA: 19b9cca | Docs | Datadog PR Page | Give us feedback! |
226061c to
5a66bbd
Compare
tbavelier
left a comment
There was a problem hiding this comment.
lgtm overall, one nit
Evnetually, we would need each feature to manage the seccomp profile instead of the change in default.go, but that's out of scope here
What does this PR do?
Add KILL capability to either the security-agent or system-probe container.
Motivation
The OSCAP wrapper makes use of the kill signal, causing it not to be killed properly.
Additional Notes
Anything else we should know when reviewing?
Minimum Agent Versions
Are there minimum versions of the Datadog Agent and/or Cluster Agent required?
Describe your test plan
Write there any instructions and details you may have to test your PR.
Checklist
bug,enhancement,refactoring,documentation,tooling, and/ordependenciesqa/skip-qalabel