You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Tekton EventListener配置securityContext?遇PodSecurity报错

关于Tekton EventListener配置securityContext的问题及临时解决方法

问题详情

能否为Tekton EventListener配置securityContext?官方文档中未找到相关配置说明,部署后EventListener组件无法正常运行,Pod状态报错如下:

Message:               pods "el-github-listener-interceptor-7b89d546dd-m6rdz" is forbidden: violates PodSecurity "restricted:latest": allowPrivilegeEscalation != false (container "event-listener" must set securityContext.allowPrivilegeEscalation=false), unrestricted capabilities (container "event-listener" must set securityContext.capabilities.drop=["ALL"]), seccompProfile (pod or container "event-listener" must set securityContext.seccompProfile.type to "RuntimeDefault" or "Localhost")

当前使用的EventListener定义:

apiVersion: triggers.tekton.dev/v1beta1
kind: EventListener
metadata:
  name: github-listener-interceptor
  namespace: tekton-pipelines
spec:
  serviceAccountName: sa-tekton-triggers
  triggers:
    - name: github-listener
      interceptors:
        - ref:
            name: "github"
          params:
            - name: "eventTypes"
              value: ["push"]
        - ref:
            name: cel
          params:
          - name: filter
            # execute only when ....
            value: extensions.changed_files.matches('src/')
      bindings:
        - ref: pipeline-reach-dashboard-binding
      template:
        ref: pipeline-reach-dashboard-template

已尝试在所有可能的位置添加securityContext配置块,但均未生效。

临时解决方法

经确认,这是Tekton Pipelines的已知问题,临时解决方法为:将EventListener及关联的触发器资源迁移至tekton-pipelines命名空间以外的其他命名空间。

内容的提问来源于stack exchange,提问作者Gary Turner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 15:07:51