You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在AKS中运行Jenkins容器:非特权模式替代方案咨询

问题

我们尝试在AKS集群中以容器形式运行Jenkins,采用Docker-in-Docker方案,需在Jenkins slave Pod的执行容器中安装Docker。原本需通过特权访问让该容器执行Docker命令,但受ConstraintTemplate k8sazurev2noprivilege策略限制,触发如下403错误:

Message: admission webhook "validation.gatekeeper.sh" denied the request: [azurepolicy-k8sazurev2noprivilege-*******] Privileged container is not allowed: custom, securityContext: {"privileged": true}. Received status: Status(apiVersion=v1, code=403, details=null, kind=Status, message=admission webhook "validation.gatekeeper.sh" denied the request: [azurepolicy-k8sazurev2noprivilege-******] Privileged container is not allowed: custom, securityContext: {"privileged": true}, metadata=ListMeta(_continue=null, remainingItemCount=null, resourceVersion=null, selfLink=null, additionalProperties={}), reason=Forbidden, status=Failure, additionalProperties={})

咨询:是否必须以特权模式运行容器?有无无需修改Azure策略约束的可行方案?

回答

是否必须以特权模式运行容器?

不是必须的。传统Docker-in-Docker(DinD)方案需要特权模式是因为要在容器内启动完整的Docker守护进程,但存在更安全的替代方案,无需开启privileged: true权限。

无需修改Azure策略约束的可行方案

  • 采用Docker-out-of-Docker(DooD)方案:直接挂载宿主机的Docker套接字(/var/run/docker.sock)到Jenkins slave容器中。容器内的Docker客户端会直接调用宿主机的Docker守护进程,不需要在容器内启动独立的Docker daemon,因此无需特权模式。

    • 配置示例(Pod定义片段):
      containers:
      - name: jenkins-slave
        image: jenkins/inbound-agent:latest
        volumeMounts:
        - name: docker-sock
          mountPath: /var/run/docker.sock
      volumes:
      - name: docker-sock
        hostPath:
          path: /var/run/docker.sock
      
    • 注意事项:需确保容器内的用户拥有宿主机Docker套接字的访问权限,可通过调整容器securityContext中的runAsUser、runAsGroup,或修改宿主机套接字的权限实现。
  • 使用Kaniko替代Docker构建镜像:Kaniko是Google推出的无守护进程镜像构建工具,完全在用户空间运行,不需要任何特权权限即可构建Docker镜像。

    • Jenkins流水线示例:
      stage('Build Image') {
          steps {
              container('kaniko') {
                  sh '''
                  /kaniko/executor \
                  --context ${WORKSPACE} \
                  --dockerfile ${WORKSPACE}/Dockerfile \
                  --destination your-registry/image:tag
                  '''
              }
          }
      }
      
    • 优势:完全符合非特权容器要求,避免了DinD的安全风险,也不依赖宿主机Docker环境。
  • 用Podman替代Docker:Podman是无守护进程的容器工具,命令行接口与Docker兼容。在Jenkins slave容器中安装Podman后,采用rootless模式运行,无需特权权限即可执行容器操作和镜像构建。

    • 配置要点:在容器中安装Podman,启用rootless模式,可通过securityContext添加必要的能力(如CAP_NET_ADMIN),但无需设置privileged: true,同时确保allowPrivilegeEscalation: false。

内容的提问来源于stack exchange,提问作者knowledge20

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 01:17:24