You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

GCP Kubernetes自动添加drop: NET_RAW,如何阻止并启用容器Ping?

问题原因与解决方法

原因分析

这种情况是GCP Kubernetes(GKE)的**Pod Security Standards(PSS)或旧版的Pod Security Policy(PSP)**强制生效导致的:

  • 若集群启用了Pod Security Admission控制器,默认对命名空间应用Restricted(受限)安全标准,该标准会自动移除NET_RAW这类高风险Linux能力——哪怕你手动添加add: ["NET_RAW"],控制器也会追加drop: ["NET_RAW"]覆盖配置。
  • 旧版GKE中若启用了默认Pod Security Policy,同样包含移除NET_RAW的规则,强制管控容器权限。

解决方法

方法1:调整命名空间的Pod Security标准

给Deployment所在命名空间设置更宽松的安全模式,比如Baseline(基线)或Privileged(特权)模式:

  1. 编辑目标命名空间的配置文件:
apiVersion: v1
kind: Namespace
metadata:
  name: 你的命名空间名称
  labels:
    pod-security.kubernetes.io/enforce: baseline
    pod-security.kubernetes.io/audit: baseline
    pod-security.kubernetes.io/warn: baseline
  1. 应用配置:kubectl apply -f 命名空间配置文件.yaml

注:Baseline模式允许使用NET_RAW,Privileged模式完全放开权限,请根据实际安全需求选择。

方法2:自定义Pod Security Policy(仅适用于旧版GKE)

如果集群仍在使用PSP(GKE 1.25及以后版本已默认弃用PSP,改用PSS),可创建允许添加NET_RAW的PSP:

  1. 创建PSP配置文件allow-net-raw-psp.yaml:
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: allow-net-raw
spec:
  privileged: false
  allowPrivilegeEscalation: true
  allowedCapabilities:
  - NET_RAW
  runAsUser:
    rule: RunAsAny
  seLinux:
    rule: RunAsAny
  supplementalGroups:
    rule: RunAsAny
  fsGroup:
    rule: RunAsAny
  1. 应用PSP:kubectl apply -f allow-net-raw-psp.yaml
  2. 创建ClusterRole绑定该PSP:
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: use-net-raw-psp
rules:
- apiGroups: ['policy']
  resources: ['podsecuritypolicies']
  verbs: ['use']
  resourceNames: ['allow-net-raw']
  1. 将ClusterRole绑定到Deployment使用的ServiceAccount(若用默认ServiceAccount,绑定命名空间的default账号):
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: use-net-raw-psp-binding
  namespace: 你的命名空间名称
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: use-net-raw-psp
subjects:
- kind: ServiceAccount
  name: default
  namespace: 你的命名空间名称
  1. 重新部署Deployment,此时PSP会允许容器添加NET_RAW权限,不会被自动移除。

方法3:使用特权容器(仅临时测试,禁止生产环境)

若只是临时测试,可将容器设为特权模式绕过权限限制:

securityContext:
  privileged: true

注意:特权容器存在严重安全风险,生产环境绝对禁止使用。

内容的提问来源于stack exchange,提问作者Mr J

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 13:18:32