Linkerd Viz部署遇PodSecurityPolicy准入失败问题排查求助
我了解PodSecurityPolicy(PSP)已被弃用,但集群仍强制要求使用。部署Linkerd Viz时,linkerd-viz命名空间下创建Pod失败,报错如下:
8m27s Warning FailedCreate replicaset/web-cb5fc858f Error creating: pods "web-cb5fc858f-" is forbidden: PodSecurityPolicy: unable to admit pod: [spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_ADMIN": capability may not be added spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_RAW": capability may not be added spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[seccomp.security.alpha.kubernetes.io/pod]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-init]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-proxy]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/web]: Forbidden: seccomp may not be set] 11m Warning FailedCreate replicaset/web-cb5fc858f Error creating: pods "web-cb5fc858f-" is forbidden: PodSecurityPolicy: unable to admit pod: [pod.metadata.annotations[seccomp.security.alpha.kubernetes.io/pod]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-init]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-proxy]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/web]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_ADMIN": capability may not be added spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_RAW": capability may not be added spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed]
已配置的PSP、Role和RoleBinding
PodSecurityPolicy配置
kind: PodSecurityPolicy metadata: labels: linkerd.io/control-plane-ns: linkerd name: linkerd-linkerd-control-plane spec: allowPrivilegeEscalation: true allowedCapabilities: - NET_ADMIN - NET_RAW fsGroup: ranges: - max: 65535 min: 1 rule: MustRunAs readOnlyRootFilesystem: true requiredDropCapabilities: - ALL runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: ranges: - max: 65535 min: 1 rule: MustRunAs volumes: - configMap - emptyDir - secret - projected - downwardAPI - persistentVolumeClaim
Role配置
apiVersion: v1 items: - apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: labels: linkerd.io/extension: viz name: psp namespace: linkerd-viz rules: - apiGroups: - policy - extensions resourceNames: - linkerd-linkerd-control-plane resources: - podsecuritypolicies verbs: - use kind: List metadata: resourceVersion: ""
RoleBinding配置
apiVersion: v1 items: - apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: labels: linkerd.io/extension: viz namespace: linkerd-viz name: viz-psp namespace: linkerd-viz roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: psp subjects: - kind: ServiceAccount name: tap namespace: linkerd-viz - kind: ServiceAccount name: web namespace: linkerd-viz - kind: ServiceAccount name: prometheus namespace: linkerd-viz - kind: ServiceAccount name: metrics-api namespace: linkerd-viz - kind: ServiceAccount name: tap-injector namespace: linkerd-viz kind: List metadata: resourceVersion: ""
看起来所有策略配置都已正确设置,请问导致该问题的原因可能是什么?
PSP未允许Seccomp注解:报错明确指出
seccomp.security.alpha.kubernetes.io/pod等Seccomp相关注解被禁止。当前PSP配置中缺少seccomp规则配置,需要在PSP的spec中添加以下内容,允许Pod使用任意Seccomp配置:spec: seccomp: rule: RunAsAnyPSP未被正确匹配:虽然配置了Role和RoleBinding,但可能存在以下情况:
- 集群中存在其他优先级更高、限制更严格的PSP,Kubernetes会选择最严格的PSP进行Pod验证,导致你的宽松PSP未被选中。可以用
kubectl get psp查看所有PSP,检查是否有其他PSP通过RBAC绑定到了linkerd-viz的ServiceAccount。 - RoleBinding遗漏了部分ServiceAccount:Linkerd Viz的proxy注入可能会使用
linkerd-proxy这类未包含在当前RoleBinding中的ServiceAccount,导致Pod创建时无法匹配到正确的PSP。
- 集群中存在其他优先级更高、限制更严格的PSP,Kubernetes会选择最严格的PSP进行Pod验证,导致你的宽松PSP未被选中。可以用
RBAC权限问题:确认Role中的
apiGroups是否适配集群版本。PSP在Kubernetes 1.16+属于policyAPI组,旧版本为extensions,当前配置包含两组是正确的,但可以通过kubectl api-resources | grep podsecuritypolicies确认集群使用的API组。requiredDropCapabilities与allowedCapabilities的冲突:当前PSP设置了
requiredDropCapabilities: - ALL,同时添加了allowedCapabilities: - NET_ADMIN - NET_RAW,逻辑上是允许先移除所有权限再添加指定能力,但如果Pod的安全上下文没有正确应用这些配置,或者PSP未被正确匹配,仍会出现权限不足的报错。
内容的提问来源于stack exchange,提问作者Iceforest

