You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Linkerd Viz部署遇PodSecurityPolicy准入失败问题排查求助

问题:Linkerd Viz部署因PodSecurityPolicy限制失败

我了解PodSecurityPolicy(PSP)已被弃用,但集群仍强制要求使用。部署Linkerd Viz时,linkerd-viz命名空间下创建Pod失败,报错如下:

8m27s       Warning   FailedCreate        replicaset/web-cb5fc858f             Error creating: pods "web-cb5fc858f-" is forbidden: PodSecurityPolicy: unable to admit pod: [spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_ADMIN": capability may not be added spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_RAW": capability may not be added spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[seccomp.security.alpha.kubernetes.io/pod]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-init]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-proxy]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/web]: Forbidden: seccomp may not be set]
11m         Warning   FailedCreate        replicaset/web-cb5fc858f             Error creating: pods "web-cb5fc858f-" is forbidden: PodSecurityPolicy: unable to admit pod: [pod.metadata.annotations[seccomp.security.alpha.kubernetes.io/pod]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-init]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/linkerd-proxy]: Forbidden: seccomp may not be set pod.metadata.annotations[container.seccomp.security.alpha.kubernetes.io/web]: Forbidden: seccomp may not be set spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_ADMIN": capability may not be added spec.initContainers[0].securityContext.capabilities.add: Invalid value: "NET_RAW": capability may not be added spec.initContainers[0].securityContext.allowPrivilegeEscalation: Invalid value: true: Allowing privilege escalation for containers is not allowed]

已配置的PSP、Role和RoleBinding

PodSecurityPolicy配置

kind: PodSecurityPolicy
metadata:
  labels:
    linkerd.io/control-plane-ns: linkerd
  name: linkerd-linkerd-control-plane
spec:
  allowPrivilegeEscalation: true
  allowedCapabilities:
  - NET_ADMIN
  - NET_RAW
  fsGroup:
    ranges:
    - max: 65535
      min: 1
    rule: MustRunAs
  readOnlyRootFilesystem: true
  requiredDropCapabilities:
  - ALL
  runAsUser:
    rule: RunAsAny
  seLinux:
    rule: RunAsAny
  supplementalGroups:
    ranges:
    - max: 65535
      min: 1
    rule: MustRunAs
  volumes:
  - configMap
  - emptyDir
  - secret
  - projected
  - downwardAPI
  - persistentVolumeClaim

Role配置

apiVersion: v1
items:
- apiVersion: rbac.authorization.k8s.io/v1
  kind: Role
  metadata:
    labels:
      linkerd.io/extension: viz
    name: psp
    namespace: linkerd-viz
  rules:
  - apiGroups:
    - policy
    - extensions
    resourceNames:
    - linkerd-linkerd-control-plane
    resources:
    - podsecuritypolicies
    verbs:
    - use
kind: List
metadata:
  resourceVersion: ""

RoleBinding配置

apiVersion: v1
items:
- apiVersion: rbac.authorization.k8s.io/v1
  kind: RoleBinding
  metadata:
    labels:
      linkerd.io/extension: viz
      namespace: linkerd-viz
    name: viz-psp
    namespace: linkerd-viz
  roleRef:
    apiGroup: rbac.authorization.k8s.io
    kind: Role
    name: psp
  subjects:
  - kind: ServiceAccount
    name: tap
    namespace: linkerd-viz
  - kind: ServiceAccount
    name: web
    namespace: linkerd-viz
  - kind: ServiceAccount
    name: prometheus
    namespace: linkerd-viz
  - kind: ServiceAccount
    name: metrics-api
    namespace: linkerd-viz
  - kind: ServiceAccount
    name: tap-injector
    namespace: linkerd-viz
kind: List
metadata:
  resourceVersion: ""

看起来所有策略配置都已正确设置,请问导致该问题的原因可能是什么?


可能的原因分析
  • PSP未允许Seccomp注解:报错明确指出seccomp.security.alpha.kubernetes.io/pod等Seccomp相关注解被禁止。当前PSP配置中缺少seccomp规则配置,需要在PSP的spec中添加以下内容,允许Pod使用任意Seccomp配置:

    spec:
      seccomp:
        rule: RunAsAny
    
  • PSP未被正确匹配:虽然配置了Role和RoleBinding,但可能存在以下情况:

    • 集群中存在其他优先级更高、限制更严格的PSP,Kubernetes会选择最严格的PSP进行Pod验证,导致你的宽松PSP未被选中。可以用kubectl get psp查看所有PSP,检查是否有其他PSP通过RBAC绑定到了linkerd-viz的ServiceAccount。
    • RoleBinding遗漏了部分ServiceAccount:Linkerd Viz的proxy注入可能会使用linkerd-proxy这类未包含在当前RoleBinding中的ServiceAccount,导致Pod创建时无法匹配到正确的PSP。
  • RBAC权限问题:确认Role中的apiGroups是否适配集群版本。PSP在Kubernetes 1.16+属于policy API组,旧版本为extensions,当前配置包含两组是正确的,但可以通过kubectl api-resources | grep podsecuritypolicies确认集群使用的API组。

  • requiredDropCapabilities与allowedCapabilities的冲突:当前PSP设置了requiredDropCapabilities: - ALL,同时添加了allowedCapabilities: - NET_ADMIN - NET_RAW,逻辑上是允许先移除所有权限再添加指定能力,但如果Pod的安全上下文没有正确应用这些配置,或者PSP未被正确匹配,仍会出现权限不足的报错。

内容的提问来源于stack exchange,提问作者Iceforest

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 01:15:06