Kubernetes: run container as a root

Viewed 1513

I do understand drawbacks of doing this, however I have image that will work only with root user running cmd within it.

Server kubernetes version is: v1.19.14. Inside my deployment.yaml I have:

spec:
  containers:
    - name: myapp
      securityContext:
        allowPrivilegeEscalation: false
        runAsUser: 0
      command: ...
      image:...

But when I describe rs I see following:

  Type     Reason        Age                From                   Message
  ----     ------        ----               ----                   -------
  Warning  FailedCreate  0s (x13 over 21s)  replicaset-controller  Error creating: pods "myapp-7cdd994c56-" is forbidden: PodSecurityPolicy: unable to admit pod: [spec.containers[0].securityContext.runAsUser: Invalid value: 0: running with the root UID is forbidden]

What do I do wrong?

1 Answers

The error message says:

PodSecurityPolicy: unable to admit pod: [spec.containers[0].securityContext.runAsUser: Invalid value: 0: running with the root UID is forbidden]

Pod Security Policy is defined in the documentation as:

[...] a cluster-level resource that controls security sensitive aspects of the pod specification. The PodSecurityPolicy objects define a set of conditions that a pod must run with in order to be accepted into the system [...]

You are using a cluster for which the Pod Security Policy forbids the use of root containers (See Pod Security Policy - Users and Groups)

You have to change the Pod Security Policy yourself or ask your cluster administrator to do so.

Note that:

PodSecurityPolicy is deprecated as of Kubernetes v1.21, and will be removed in v1.25.

Related