Support

Taking action to secure our IBM Cloud Container Service against recent Spectre and Meltdown security vulnerabilities

Share this post:

What’s happening

We’re taking action to secure our IBM Cloud Container Service against the recent Spectre and Meltdown security vulnerabilities.
We’ve been working closely with our vendors and IBM Cloud Infrastructure teams concerning the security vulnerability announced on January 3, 2018. This vulnerability has the potential to allow those with malicious intent to gather sensitive data from computing devices. Intel believes these exploits do not have the potential to corrupt, modify, or delete data.

 

What’s been done

The hypervisors have already been patched (see IBM Cloud Infrastructure Blog). Now, the kernel for all VMs that run Kubernetes worker nodes must be updated.

We have updated the cloud image that is used to create IBM Cloud Container Service standard clusters. The update includes the vulnerability mitigation updates as recommended by Ubuntu (see Ubuntu Spectre and Meltdown).

 

How do I mitigate the issue

As a consumer of the service, you should take action to mitigate the issue in your worker nodes. You can choose between the following options:
  • Reload: Reload the configuration files of your Kubernetes cluster worker nodes. To reload, run bx cs worker-reload <my_cluster> <worker_node1> <worker_node2>.
  • Update: Update the version of your Kubernetes cluster worker nodes. This might require that you update your deployment YAML files. See the release notes for more details. To update, run bx cs worker-update <my_cluster> <worker_node1> <worker_node2>.
 When you reload or update your worker nodes, they reboot and install the new image. After the worker nodes reload or update, verify that your Kubernetes pods are recreated on the worker nodes.
 

Lite clusters will be patched beginning Monday 15th January by the IBM Cloud Container Service SRE automation.

 

How to check my version

You can check the version of your workers using the “bx cs workers <my_clusterid>”

Your cluster should be on of the following versions:

  • 1.5.6_1506
  • 1.7.4_1506
  • 1.8.6_1504

Example output:

Questions or comments

Please join us on our public Slack channel at https://ibm-container-service.slack.com or raise a support ticket if you have any issues.

Distinguished Engineer, Site Reliability Engineering, IBM Cloud

More Support stories
January 4, 2019

Recent Kubernetes Security Disclosures for Dashboard and API Server Proxy

There have been two security Kubernetes security disclosures on Friday, January 4, 2019. Here are the details of these disclosures and how to mitigate them while using the IBM Cloud Kubernetes Service.

Continue reading

December 4, 2018

Taking Action to Secure Our IBM Cloud Kubernetes Service Against Recent Kubernetes Security Vulnerabilities

We’re taking action to secure our IBM Cloud Kubernetes Service against the recent Kubernetes security vulnerabilities. IBM Cloud Kubernetes Service is affected by the detailed vulnerabilities that, in some cases, allow unauthorized access to Kubernetes and/or trusted user privilege escalation.

Continue reading

November 30, 2018

Life Just Got Easier with the Enhanced IBM Cloud Support Center

Starting today, we are excited to release the enhanced IBM Cloud Support Center—a place that provides you with a simplified and unified experience for getting IBM Cloud support.

Continue reading