Files
kuboard-press/learning/k8s-intermediate/workload/pod-privileged.md
huanqing.shao 0fa6b590f5 Service
2019-09-18 22:59:49 +08:00

13 lines
731 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
description: 在 Kubernetes 中为 Pod 中的容器开启 privileged 模式
---
# 容器组 - Privileged 模式
## Privilged 模式运行容器
Pod 中的任何容器都可以开启 privileged 模式,只需要
Any container in a Pod can enable privileged mode, using the privileged flag on the security context of the container spec. This is useful for containers that want to use Linux capabilities like manipulating the network stack and accessing devices. Processes within the container get almost the same privileges that are available to processes outside a container. With privileged mode, it should be easier to write network and volume plugins as separate Pods that dont need to be compiled into the kubelet.