Kubernetes Commands for Enhancing Security
allowPrivilegeEscalation
Initial Example
apiVersion: v1
kind: Pod
metadata:
name: privileged-pod
spec:
containers:
- name: main-container
image: nginx
securityContext:
allowPrivilegeEscalation: true # This violates the rule
initContainers:
- name: init-container
image: busybox
command: ["sh", "-c", "echo Init container running"]
# This violates the rule (securityContext.allowPrivilegeEscalation is unset)Compliant Example
runAsUser
Initial Example
Compliant Example
runAsNonRoot
Initial Example
Compliant Example
Tutorial
Last updated
