You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rancher环境下NeuVector控制器Pod部署失败求助

NeuVector控制器Pod部署失败(PodSecurityPolicy限制)解决方案

报错信息

Pods "neuvector-controller-pod-9855df76c-" is forbidden: PodSecurityPolicy: unable to admit pod: [spec.volumes[0]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[1]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[2]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[3]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.containers[0].securityContext.privileged: Invalid value: true: Privileged containers are not allowed]; Deployment does not have minimum availability.

核心原因

集群启用了PodSecurityPolicy(PSP),当前规则禁止使用hostPath卷和特权容器,但NeuVector控制器Pod依赖这些特性运行。

解决步骤

1. 定义适配NeuVector的PodSecurityPolicy

创建neuvector-psp.yaml文件,内容如下:

apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: neuvector-psp
spec:
  privileged: true
  allowPrivilegeEscalation: true
  allowedHostPaths:
  - pathPrefix: "/var/run/docker.sock"
  - pathPrefix: "/proc"
  - pathPrefix: "/sys/fs/cgroup"
  - pathPrefix: "/var/log/neuvector"
  volumes:
  - "hostPath"
  - "secret"
  - "configMap"
  runAsUser:
    rule: "RunAsAny"
  seLinux:
    rule: "RunAsAny"
  supplementalGroups:
    rule: "RunAsAny"
  fsGroup:
    rule: "RunAsAny"

执行命令应用该PSP:
kubectl apply -f neuvector-psp.yaml

2. 绑定PSP权限到NeuVector服务账户

创建neuvector-psp-rbac.yaml文件,内容如下(注意替换命名空间为你的NeuVector安装目录):

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: neuvector-psp-role
rules:
- apiGroups: ['policy']
  resources: ['podsecuritypolicies']
  verbs: ['use']
  resourceNames: ['neuvector-psp']
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: neuvector-psp-binding
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: neuvector-psp-role
subjects:
- kind: ServiceAccount
  name: neuvector-controller-sa
  namespace: neuvector  # 替换为实际安装的命名空间

执行命令应用RBAC配置:
kubectl apply -f neuvector-psp-rbac.yaml

3. 触发控制器Pod重建

删除当前失败的Pod,让Deployment重新创建符合权限要求的Pod:
kubectl delete pod -l app=neuvector-controller -n neuvector

或者直接重启Deployment:
kubectl rollout restart deployment neuvector-controller -n neuvector

4. 验证部署结果

检查NeuVector控制器Pod状态:
kubectl get pods -n neuvector

内容的提问来源于stack exchange,提问作者Hamza Nasir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 17:26:05