You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AKS中Helm安装Grafana7.5 loki-stack报容器特权提升被拒问题

故障现象

在AKS集群通过Helm部署7.5版本Grafana loki-stack时,ReplicaSet创建失败,Gatekeeper准入webhook拦截报错如下:

Warning  FailedCreate  12s (x13 over 33s)  replicaset-controller  Error creating: admission webhook "validation.gatekeeper.sh" denied the request: [azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana-sc-dashboard
[azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana
[azurepolicy-k8sazurecontainernoprivilegees-d30fc4a5d3050e7c7bd6] Privilege escalation container is not allowed: grafana-sc-datasources

触发故障的原始安装命令:

helm upgrade --install --namespace=mon-eval loki . --set grafana.enabled=true,prometheus.enabled=true,prometheus.alertmanager.persistentVolume.enabled=false,prometheus.server.persistentVolume.enabled=false,loki.persistence.enabled=false
根因

AKS集群默认启用的Azure内置安全策略容器禁止特权提升会在资源创建阶段做校验,要求所有工作负载的容器securityContext.allowPrivilegeEscalation必须为false,禁止进程获取超出父进程的权限。
loki-stack 7.5版本绑定的Grafana子Chart默认未显式配置Grafana主容器、dashboard sidecar(grafana-sc-dashboard)、datasource sidecar(grafana-sc-datasources)的该参数,继承的默认值为true,直接触发策略拦截。

修复方案

方案1:Helm参数覆盖安全上下文配置(生产环境推荐)

直接在安装命令中追加参数,显式关闭三个相关容器的特权提升权限,同时配置非root用户运行,完全符合AKS安全策略要求,无额外安全风险。
修改后的完整安装命令:

helm upgrade --install --namespace=mon-eval loki . \
--set grafana.enabled=true,prometheus.enabled=true \
--set prometheus.alertmanager.persistentVolume.enabled=false \
--set prometheus.server.persistentVolume.enabled=false \
--set loki.persistence.enabled=false \
--set grafana.securityContext.allowPrivilegeEscalation=false \
--set grafana.securityContext.runAsNonRoot=true \
--set grafana.sidecar.dashboards.securityContext.allowPrivilegeEscalation=false \
--set grafana.sidecar.dashboards.securityContext.runAsNonRoot=true \
--set grafana.sidecar.datasources.securityContext.allowPrivilegeEscalation=false \
--set grafana.sidecar.datasources.securityContext.runAsNonRoot=true

如果使用自定义values.yaml部署,直接在文件中追加以下配置即可:

grafana:
  securityContext:
    allowPrivilegeEscalation: false
    runAsNonRoot: true
  sidecar:
    dashboards:
      securityContext:
        allowPrivilegeEscalation: false
        runAsNonRoot: true
    datasources:
      securityContext:
        allowPrivilegeEscalation: false
        runAsNonRoot: true

部署完成后可通过以下命令验证配置生效:

# 确认Grafana Pod处于Running状态
kubectl get pod -n mon-eval | grep grafana
# 验证容器特权提升已禁用,返回值NoNewPrivs: 1即为生效
kubectl exec -n mon-eval <替换为实际Grafana Pod名> -c grafana -- cat /proc/1/status | grep NoNewPrivs

方案2:命名空间策略豁免(仅测试环境临时使用)

如果因特殊场景无法调整容器配置,可在Azure Policy控制台为mon-eval命名空间添加该策略的豁免规则,跳过该命名空间下的特权提升校验。该方案会降低命名空间安全基线,不建议生产环境使用。

内容的提问来源于stack exchange,提问作者Alex Rubio

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.27 22:36:23