3 ms·
Any container not running as normal user is considered privileged. A root container is privileged bit isn't --privileged. An important distinction. From a secu
by auspex 7y ago
Any container not running as normal user is considered privileged. A root container is privileged bit isn't --privileged.
An important distinction. From a security point of view running --privileged is just lazy. If you need things like kernel permissions etc, run as root and then request kernel permissions in the deployment yaml... and if running something like k8s make sure to apply a pod security spec limiting permissions and the apply the right seccomp profile.