You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在AWS EKS中为无对应参数的预定义Helm Chart启用seccomp RuntimeDefault

在AWS EKS中为无seccomp参数的Helm Chart启用RuntimeDefault配置

以下是三种无需下载修改Chart本地文件的实现方式:

方法1:使用Helm --set 参数直接注入安全上下文

如果Chart的Deployment/DaemonSet等资源的Pod模板支持通过Helm values注入安全上下文(即使values.yml未定义该参数),可在helm install或helm upgrade时直接通过--set添加seccomp配置:

命令示例:

helm install <release-name> <chart-repo>/<chart-name> \
  --namespace <your-namespace> \
  --set template.spec.podSecurityContext.seccompProfile.type=RuntimeDefault

注意事项:

  • 若Chart的安全上下文定义在容器级别而非Pod级别,需调整路径为template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault([0]对应第一个容器,多容器需逐个设置)。
  • 执行前可用helm template验证注入效果:
    helm template <release-name> <chart-repo>/<chart-name> \
      --set template.spec.podSecurityContext.seccompProfile.type=RuntimeDefault \
      | grep -A5 -B5 seccompProfile
    

方法2:通过Pod Security Standards (PSS) 强制启用Seccomp

利用EKS原生支持的Pod Security Admission(PSA),在Namespace级别配置强制策略,要求所有Pod使用RuntimeDefault seccomp profile:

步骤:

  1. 为目标Namespace添加标签,启用restricted策略(该策略默认要求seccomp为RuntimeDefault):
    kubectl label namespace <your-namespace> pod-security.kubernetes.io/enforce=restricted
    kubectl label namespace <your-namespace> pod-security.kubernetes.io/warn=restricted
    kubectl label namespace <your-namespace> pod-security.kubernetes.io/audit=restricted
    
  2. 验证策略生效:部署Helm Chart后,检查Pod的seccomp配置:
    kubectl get pod <pod-name> -n <your-namespace> -o jsonpath='{.spec.securityContext.seccompProfile}'
    

注意事项:

  • restricted策略包含其他安全限制(如禁止特权容器、强制非root用户等),若Chart的Pod不符合这些规则,部署会失败。可自定义PSS策略或使用baseline策略(仅在warn/audit模式提示seccomp问题)。
  • EKS 1.23及以上版本默认启用PSA,低版本需手动开启。

方法3:使用Helm Post-Renderer结合Kustomize

通过Helm的post-renderer功能,用Kustomize在渲染Chart后自动patch添加seccomp配置:

步骤:

  1. 创建Kustomize目录(如kustomize-seccomp),并编写kustomization.yaml:
    apiVersion: kustomize.config.k8s.io/v1beta1
    kind: Kustomization
    patches:
      - target:
          kind: Deployment
          name: <chart-deployment-name> # 替换为Chart中Deployment的实际名称
        patch: |-
          - op: add
            path: /spec/template/spec/securityContext/seccompProfile
            value:
              type: RuntimeDefault
    
  2. 执行Helm部署时指定post-renderer:
    helm install <release-name> <chart-repo>/<chart-name> \
      --namespace <your-namespace> \
      --post-renderer kustomize build kustomize-seccomp/
    

注意事项:

  • 需提前通过helm template命令确认Chart中Deployment的名称。
  • 该方法适用于复杂配置修改场景,支持同时patch多个资源。

内容的提问来源于stack exchange,提问作者Abdullah Khawer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 22:05:20