You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OpenShift BuildConfig中添加容器能力(如CHECKPOINT_RESTORE)?

在OpenShift BuildConfig中添加容器能力(Docker构建策略)

可以在BuildConfig里配置你需要的容器能力和安全选项,对应你用podman构建时的--cap-add和--security-opt参数,只需在BuildConfig的spec段添加securityContext字段即可实现。

以下是修改后的完整配置:

kind: BuildConfig
metadata:
  name: modresorts-build
  labels:
    app: modresorts-build
spec:
  # 配置构建Pod的安全上下文,添加所需能力并关闭seccomp限制
  securityContext:
    capabilities:
      add:
        - CHECKPOINT_RESTORE
        - SYS_PTRACE
        - SETPCAP
    seccompProfile:
      type: Unconfined
  source:
    type: Git
    git:
      uri: https://github.com/bpaskin/...
  strategy:
    type: Docker
    dockerStrategy:
      dockerfilePath: Dockerfile
      from:
        kind: ImageStreamTag
        namespace: demo
        name: liberty:liberty
  output:
    to:
      kind: ImageStreamTag
      name: modresorts-app:latest
  triggers:
     - type: ImageChange

说明:

  • securityContext.capabilities.add:对应命令行的--cap-add参数,将所需的容器能力逐一列出
  • securityContext.seccompProfile.type: Unconfined:对应命令行的--security-opt seccomp=unconfined,解除seccomp的限制

注意:如果你的OpenShift集群有严格的安全约束,可能需要先调整集群的SecurityContextConstraints(SCC),允许构建Pod添加这些能力和使用非受限的seccomp配置。

内容的提问来源于stack exchange,提问作者Brian S Paskin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.16 18:30:13