Tekton Pipeline执行报错:违反PodSecurity restricted策略求助
解决Tekton PipelineRun的PodSecurity策略违规问题
问题分析
当前执行PipelineRun时触发的错误违反了Kubernetes restricted:latest PodSecurity策略,需满足以下强制要求:
- 所有容器必须设置
securityContext.allowPrivilegeEscalation=false - 所有容器必须设置
securityContext.capabilities.drop=["ALL"] - Pod或容器必须设置
securityContext.runAsNonRoot=true - Pod或容器必须设置
securityContext.seccompProfile.type为RuntimeDefault或Localhost
解决方案
方法一:修改PipelineRun的PodTemplate添加安全上下文
直接在PipelineRun的podTemplate中配置Pod级和容器级安全上下文,让所有任务容器自动符合策略要求:
apiVersion: tekton.dev/v1beta1 kind: PipelineRun metadata: name: ft-common-run namespace: tekton-pipelines spec: serviceAccountName: git-service-account pipelineRef: name: ft-common podTemplate: securityContext: fsGroup: 65532 # Pod级安全配置,所有容器继承 runAsNonRoot: true seccompProfile: type: RuntimeDefault # 统一配置所有容器的安全上下文 containerSecurityContext: allowPrivilegeEscalation: false capabilities: drop: ["ALL"] workspaces: - name: shared-workspace volumeClaimTemplate: spec: accessModes: - ReadWriteOnce resources: requests: storage: 2Gi - name: gcp-secret secret: secretName: gcp-service-account-key - name: git-secret secret: secretName: git-ssh-key-secret params: - name: repo-url value: git@bitbucket.org:anandjaisy/common.git
方法二:升级git-clone任务到适配策略的新版本
你当前使用的git-clone 0.9版本较旧,0.13+版本已内置符合restricted策略的安全配置,执行以下命令升级:
kubectl apply -f https://raw.githubusercontent.com/tektoncd/catalog/main/task/git-clone/0.13/git-clone.yaml
升级后无需修改现有PipelineRun配置,新的git-clone任务会自动应用合规的安全设置。
方法三:给tekton-pipelines命名空间添加PodSecurity豁免(不推荐)
若需临时绕过策略(会降低集群安全性),可给目标命名空间添加豁免标签:
kubectl label namespace tekton-pipelines pod-security.kubernetes.io/enforce=privileged
验证
修改配置后重新创建PipelineRun:
kubectl apply -f pipeline-run.yaml
查看Pod运行状态确认问题解决:
kubectl get pods -n tekton-pipelines
内容的提问来源于stack exchange,提问作者San Jaisy
相关产品推荐
相关产品推荐

