You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在cdk8s中为容器配置Capabilities?

用cdk8s配置容器Capabilities(添加NET_ADMIN)

在cdk8s中,你可以通过定义容器的securityContext属性,对应实现Kubernetes YAML里的Capabilities配置,以下是具体实现示例:

TypeScript 示例

import { Pod, Container } from 'cdk8s';
import { Construct } from 'constructs';

export class MyPod extends Construct {
  constructor(scope: Construct, id: string) {
    super(scope, id);

    new Pod(this, 'my-pod', {
      containers: [
        {
          name: 'my-container',
          image: 'nginx:alpine',
          // 配置容器安全上下文,添加NET_ADMIN能力
          securityContext: {
            capabilities: {
              add: ['NET_ADMIN']
            }
          }
        }
      ]
    });
  }
}

Python 示例

from constructs import Construct
import cdk8s
from cdk8s import Pod, Container

class MyPod(Construct):
    def __init__(self, scope: Construct, id: str):
        super().__init__(scope, id)

        Pod(self, 'my-pod',
            containers=[
                Container(
                    name='my-container',
                    image='nginx:alpine',
                    security_context={
                        'capabilities': {
                            'add': ['NET_ADMIN']
                        }
                    }
                )
            ])

上述代码会生成你所需的Kubernetes YAML配置片段,部署后目标容器将获得NET_ADMIN权限。

内容的提问来源于stack exchange,提问作者onin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 20:05:33