망지로그

CKA - security context 본문

Kubernetes

CKA - security context

망지v 2024. 7. 1. 18:20

https://kubernetes.io/docs/tasks/configure-pod-container/security-context/

 

Configure a Security Context for a Pod or Container

A security context defines privilege and access control settings for a Pod or Container. Security context settings include, but are not limited to: Discretionary Access Control: Permission to access an object, like a file, is based on user ID (UID) and gro

kubernetes.io

 

apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo-4
spec:
  containers:
  - name: sec-ctx-4
    image: gcr.io/google-samples/hello-app:2.0
    securityContext:
      capabilities:
        add: ["NET_ADMIN", "SYS_TIME"]

security context capa 설정

apiVersion: v1
kind: Pod
metadata:
  name: security-context-demo-2
spec:
  securityContext:
    runAsUser: 1000
  containers:
  - name: sec-ctx-demo-2
    image: gcr.io/google-samples/hello-app:2.0
    securityContext:
      runAsUser: 2000
      allowPrivilegeEscalation: false

기본적으로 run as user 1000으로 설정되고 특정 컨테이너에서 다시 옵션 설정해주면 그 설정이 반영됨

'Kubernetes' 카테고리의 다른 글

CKA- pv,pvc  (0) 2024.07.02
CKA - networkpolicy  (0) 2024.07.02
CKA - secrets;private registry  (0) 2024.07.01
CKA- service account  (0) 2024.07.01
CKA - RBAC; Cluster Role, cluster role binding  (0) 2024.07.01