GCP Kubernetes自动添加drop: NET_RAW,如何阻止并启用容器Ping?
问题原因与解决方法
原因分析
这种情况是GCP Kubernetes(GKE)的**Pod Security Standards(PSS)或旧版的Pod Security Policy(PSP)**强制生效导致的:
- 若集群启用了Pod Security Admission控制器,默认对命名空间应用
Restricted(受限)安全标准,该标准会自动移除NET_RAW这类高风险Linux能力——哪怕你手动添加add: ["NET_RAW"],控制器也会追加drop: ["NET_RAW"]覆盖配置。 - 旧版GKE中若启用了默认Pod Security Policy,同样包含移除
NET_RAW的规则,强制管控容器权限。
解决方法
方法1:调整命名空间的Pod Security标准
给Deployment所在命名空间设置更宽松的安全模式,比如Baseline(基线)或Privileged(特权)模式:
- 编辑目标命名空间的配置文件:
apiVersion: v1 kind: Namespace metadata: name: 你的命名空间名称 labels: pod-security.kubernetes.io/enforce: baseline pod-security.kubernetes.io/audit: baseline pod-security.kubernetes.io/warn: baseline
- 应用配置:
kubectl apply -f 命名空间配置文件.yaml
注:
Baseline模式允许使用NET_RAW,Privileged模式完全放开权限,请根据实际安全需求选择。
方法2:自定义Pod Security Policy(仅适用于旧版GKE)
如果集群仍在使用PSP(GKE 1.25及以后版本已默认弃用PSP,改用PSS),可创建允许添加NET_RAW的PSP:
- 创建PSP配置文件
allow-net-raw-psp.yaml:
apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: name: allow-net-raw spec: privileged: false allowPrivilegeEscalation: true allowedCapabilities: - NET_RAW runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny fsGroup: rule: RunAsAny
- 应用PSP:
kubectl apply -f allow-net-raw-psp.yaml - 创建ClusterRole绑定该PSP:
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: use-net-raw-psp rules: - apiGroups: ['policy'] resources: ['podsecuritypolicies'] verbs: ['use'] resourceNames: ['allow-net-raw']
- 将ClusterRole绑定到Deployment使用的ServiceAccount(若用默认ServiceAccount,绑定命名空间的default账号):
apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: use-net-raw-psp-binding namespace: 你的命名空间名称 roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: use-net-raw-psp subjects: - kind: ServiceAccount name: default namespace: 你的命名空间名称
- 重新部署Deployment,此时PSP会允许容器添加
NET_RAW权限,不会被自动移除。
方法3:使用特权容器(仅临时测试,禁止生产环境)
若只是临时测试,可将容器设为特权模式绕过权限限制:
securityContext: privileged: true
注意:特权容器存在严重安全风险,生产环境绝对禁止使用。
内容的提问来源于stack exchange,提问作者Mr J
相关产品推荐
相关产品推荐

