AKS中Helm安装Grafana7.5 loki-stack报容器特权提升被拒问题
故障现象
在AKS集群通过Helm部署7.5版本Grafana loki-stack时,ReplicaSet创建失败,Gatekeeper准入webhook拦截报错如下:
Warning FailedCreate 12s (x13 over 33s) replicaset-controller Error creating: admission webhook "validation.gatekeeper.sh" denied the request: [azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana-sc-dashboard [azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana [azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana-sc-datasources
触发故障的原始安装命令:
helm upgrade --install --namespace=mon-eval loki . --set grafana.enabled=true,prometheus.enabled=true,prometheus.alertmanager.persistentVolume.enabled=false,prometheus.server.persistentVolume.enabled=false,loki.persistence.enabled=false
根因
AKS集群默认启用的Azure内置安全策略容器禁止特权提升会在资源创建阶段做校验,要求所有工作负载的容器securityContext.allowPrivilegeEscalation必须为false,禁止进程获取超出父进程的权限。
loki-stack 7.5版本绑定的Grafana子Chart默认未显式配置Grafana主容器、dashboard sidecar(grafana-sc-dashboard)、datasource sidecar(grafana-sc-datasources)的该参数,继承的默认值为true,直接触发策略拦截。
修复方案
方案1:Helm参数覆盖安全上下文配置(生产环境推荐)
直接在安装命令中追加参数,显式关闭三个相关容器的特权提升权限,同时配置非root用户运行,完全符合AKS安全策略要求,无额外安全风险。
修改后的完整安装命令:
helm upgrade --install --namespace=mon-eval loki . \ --set grafana.enabled=true,prometheus.enabled=true \ --set prometheus.alertmanager.persistentVolume.enabled=false \ --set prometheus.server.persistentVolume.enabled=false \ --set loki.persistence.enabled=false \ --set grafana.securityContext.allowPrivilegeEscalation=false \ --set grafana.securityContext.runAsNonRoot=true \ --set grafana.sidecar.dashboards.securityContext.allowPrivilegeEscalation=false \ --set grafana.sidecar.dashboards.securityContext.runAsNonRoot=true \ --set grafana.sidecar.datasources.securityContext.allowPrivilegeEscalation=false \ --set grafana.sidecar.datasources.securityContext.runAsNonRoot=true
如果使用自定义values.yaml部署,直接在文件中追加以下配置即可:
grafana: securityContext: allowPrivilegeEscalation: false runAsNonRoot: true sidecar: dashboards: securityContext: allowPrivilegeEscalation: false runAsNonRoot: true datasources: securityContext: allowPrivilegeEscalation: false runAsNonRoot: true
部署完成后可通过以下命令验证配置生效:
# 确认Grafana Pod处于Running状态 kubectl get pod -n mon-eval | grep grafana # 验证容器特权提升已禁用,返回值NoNewPrivs: 1即为生效 kubectl exec -n mon-eval <替换为实际Grafana Pod名> -c grafana -- cat /proc/1/status | grep NoNewPrivs
方案2:命名空间策略豁免(仅测试环境临时使用)
如果因特殊场景无法调整容器配置,可在Azure Policy控制台为mon-eval命名空间添加该策略的豁免规则,跳过该命名空间下的特权提升校验。该方案会降低命名空间安全基线,不建议生产环境使用。
内容的提问来源于stack exchange,提问作者Alex Rubio
相关产品推荐
相关产品推荐

