Rancher环境下NeuVector控制器Pod部署失败求助
报错信息
Pods "neuvector-controller-pod-9855df76c-" is forbidden: PodSecurityPolicy: unable to admit pod: [spec.volumes[0]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[1]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[2]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.volumes[3]: Invalid value: "hostPath": hostPath volumes are not allowed to be used spec.containers[0].securityContext.privileged: Invalid value: true: Privileged containers are not allowed]; Deployment does not have minimum availability.
核心原因
集群启用了PodSecurityPolicy(PSP),当前规则禁止使用hostPath卷和特权容器,但NeuVector控制器Pod依赖这些特性运行。
解决步骤
1. 定义适配NeuVector的PodSecurityPolicy
创建neuvector-psp.yaml文件,内容如下:
apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: name: neuvector-psp spec: privileged: true allowPrivilegeEscalation: true allowedHostPaths: - pathPrefix: "/var/run/docker.sock" - pathPrefix: "/proc" - pathPrefix: "/sys/fs/cgroup" - pathPrefix: "/var/log/neuvector" volumes: - "hostPath" - "secret" - "configMap" runAsUser: rule: "RunAsAny" seLinux: rule: "RunAsAny" supplementalGroups: rule: "RunAsAny" fsGroup: rule: "RunAsAny"
执行命令应用该PSP:kubectl apply -f neuvector-psp.yaml
2. 绑定PSP权限到NeuVector服务账户
创建neuvector-psp-rbac.yaml文件,内容如下(注意替换命名空间为你的NeuVector安装目录):
apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: neuvector-psp-role rules: - apiGroups: ['policy'] resources: ['podsecuritypolicies'] verbs: ['use'] resourceNames: ['neuvector-psp'] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: neuvector-psp-binding roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: neuvector-psp-role subjects: - kind: ServiceAccount name: neuvector-controller-sa namespace: neuvector # 替换为实际安装的命名空间
执行命令应用RBAC配置:kubectl apply -f neuvector-psp-rbac.yaml
3. 触发控制器Pod重建
删除当前失败的Pod,让Deployment重新创建符合权限要求的Pod:kubectl delete pod -l app=neuvector-controller -n neuvector
或者直接重启Deployment:kubectl rollout restart deployment neuvector-controller -n neuvector
4. 验证部署结果
检查NeuVector控制器Pod状态:kubectl get pods -n neuvector
内容的提问来源于stack exchange,提问作者Hamza Nasir

