K8s privileged

Jmnote bot (토론 | 기여)님의 2020년 11월 2일 (월) 00:44 판 (봇: 자동으로 텍스트 교체 (-</source> +</syntaxhighlight>))

1 개요

k8s privileged
쿠버네티스 privileged

<source lang='yaml'> apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata:

 name: example

spec:

 privileged: false  # Don't allow privileged pods!
 # The rest fills in some required fields.
 seLinux:
   rule: RunAsAny
 supplementalGroups:
   rule: RunAsAny
 runAsUser:
   rule: RunAsAny
 fsGroup:
   rule: RunAsAny
 volumes:
 - '*'

</syntaxhighlight> <source lang='yaml'> ... spec:

 template:
   spec:
     initContainers:
     - name: configure-sysctl
       image: busybox
       securityContext:
         runAsUser: 0
         privileged: true
       command: ["sysctl", "-w", "vm.max_map_count=262144"]

</syntaxhighlight> <source lang='yaml'> ... spec:

 template:
   spec:
     initContainers:
     - name: init-sysctl
       image: busybox:1.27.2
       command:
       - sysctl
       - -w
       - vm.max_map_count=262144
       securityContext:
         privileged: true

</syntaxhighlight>

2 같이 보기

3 참고

문서 댓글 ({{ doc_comments.length }})
{{ comment.name }} {{ comment.created | snstime }}