3 ms·
Honestly, I don’t know, but my guess is that it had some things turned off by default. Actually K8s is the most encouraging project in this regard in that it ha
by hacknat 8y ago
Honestly, I don’t know, but my guess is that it had some things turned off by default. Actually K8s is the most encouraging project in this regard in that it has opinions about how containers should work so they are slowly adding all the secure options by default when containers are orchestrated to the various runtimes. There are only a few features left that remain to be turned on (user namespacing being the most notable).
- technofiend 8y agoI paraphrased you by cutting down your comment, hope that's OK. >Actually K8s [...] are slowly adding all the secure options by default [...] (user namespacing being the most notable). K8's RBAC is nice, and in particular auth-delegator really helps with odd duck integration for the enterprise. But k8s is reliant on OS features to make user namespaces happen and Redhat customers are still waiting for Redhat to backport a newer version of shadow-utils [1] [2] to RHEL 7 so that user namespacing works there. Given enterprise certification and release cycles "Wait for RHEL 8" isn't really a good answer for those kind of customers. I'm not disagreeing with you, just saying some features of kubernetes aren't available everywhere. Personally I'd really like to see user namespaces come to RHEL 7 as it helps with removing or mitigating privileged access. [1] https://bugzilla.redhat.com/show_bug.cgi?id=1498628 https://bugzilla.redhat.com/show_bug.cgi?id=1498628 [2] https://access.redhat.com/solutions/3657531 https://access.redhat.com/solutions/3657531