【发布时间】:2022-09-28 00:02:38
【问题描述】:
强制/阻止在运行托管节点的 EKS 集群中运行的根容器并应用于所有命名空间(kube-system 除外)v1.22+ 的最佳方法是什么?我尝试了以下但根容器仍然能够运行。这是最新的方法https://kubernetes.io/docs/tutorials/security/cluster-level-pss/吗?
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
name: pod-security
spec:
privileged: true
seLinux:
rule: \'MustRunAs\'
ranges:
- min: 1
max: 65535
supplementalGroups:
rule: \'MustRunAs\'
ranges:
- min: 1
max: 65535
runAsUser:
rule: \'MustRunAs\'
ranges:
- min: 1
max: 65535
fsGroup:
rule: \'MustRunAs\'
ranges:
- min: 1
max: 65535
volumes:
- \'*\'
标签: kubernetes amazon-eks