如何在AWS EKS中为无对应参数的预定义Helm Chart启用seccomp RuntimeDefault
在AWS EKS中为无seccomp参数的Helm Chart启用RuntimeDefault配置
以下是三种无需下载修改Chart本地文件的实现方式:
方法1:使用Helm --set 参数直接注入安全上下文
如果Chart的Deployment/DaemonSet等资源的Pod模板支持通过Helm values注入安全上下文(即使values.yml未定义该参数),可在helm install或helm upgrade时直接通过--set添加seccomp配置:
命令示例:
helm install <release-name> <chart-repo>/<chart-name> \ --namespace <your-namespace> \ --set template.spec.podSecurityContext.seccompProfile.type=RuntimeDefault
注意事项:
- 若Chart的安全上下文定义在容器级别而非Pod级别,需调整路径为
template.spec.containers[0].securityContext.seccompProfile.type=RuntimeDefault([0]对应第一个容器,多容器需逐个设置)。 - 执行前可用
helm template验证注入效果:helm template <release-name> <chart-repo>/<chart-name> \ --set template.spec.podSecurityContext.seccompProfile.type=RuntimeDefault \ | grep -A5 -B5 seccompProfile
方法2:通过Pod Security Standards (PSS) 强制启用Seccomp
利用EKS原生支持的Pod Security Admission(PSA),在Namespace级别配置强制策略,要求所有Pod使用RuntimeDefault seccomp profile:
步骤:
- 为目标Namespace添加标签,启用
restricted策略(该策略默认要求seccomp为RuntimeDefault):kubectl label namespace <your-namespace> pod-security.kubernetes.io/enforce=restricted kubectl label namespace <your-namespace> pod-security.kubernetes.io/warn=restricted kubectl label namespace <your-namespace> pod-security.kubernetes.io/audit=restricted - 验证策略生效:部署Helm Chart后,检查Pod的seccomp配置:
kubectl get pod <pod-name> -n <your-namespace> -o jsonpath='{.spec.securityContext.seccompProfile}'
注意事项:
restricted策略包含其他安全限制(如禁止特权容器、强制非root用户等),若Chart的Pod不符合这些规则,部署会失败。可自定义PSS策略或使用baseline策略(仅在warn/audit模式提示seccomp问题)。- EKS 1.23及以上版本默认启用PSA,低版本需手动开启。
方法3:使用Helm Post-Renderer结合Kustomize
通过Helm的post-renderer功能,用Kustomize在渲染Chart后自动patch添加seccomp配置:
步骤:
- 创建Kustomize目录(如
kustomize-seccomp),并编写kustomization.yaml:apiVersion: kustomize.config.k8s.io/v1beta1 kind: Kustomization patches: - target: kind: Deployment name: <chart-deployment-name> # 替换为Chart中Deployment的实际名称 patch: |- - op: add path: /spec/template/spec/securityContext/seccompProfile value: type: RuntimeDefault - 执行Helm部署时指定post-renderer:
helm install <release-name> <chart-repo>/<chart-name> \ --namespace <your-namespace> \ --post-renderer kustomize build kustomize-seccomp/
注意事项:
- 需提前通过
helm template命令确认Chart中Deployment的名称。 - 该方法适用于复杂配置修改场景,支持同时patch多个资源。
内容的提问来源于stack exchange,提问作者Abdullah Khawer
相关产品推荐
相关产品推荐

