You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

RKE2 Kubernetes集群部署pgAdmin因PSP问题致Pod崩溃如何解决

RKE2集群部署pgAdmin PSP权限故障排查与解决

问题背景

计划在RKE2 Kubernetes集群上部署pgAdmin用于数据库访问,当前pgAdmin Pod持续崩溃,初步判断为PSP(PodSecurityPolicy)相关问题。已知PSP已被废弃,团队后续计划切换至OPA作为策略引擎,需要在过渡阶段实现pgAdmin正常运行。

初始部署配置

使用如下Deployment与Service配置部署:

apiVersion: apps/v1
kind: Deployment
metadata:
  name: pgadmin
spec:
  selector:
   matchLabels:
    app: pgadmin
  replicas: 1
  template:
    metadata:
      labels:
        app: pgadmin
    spec:
      containers:
        - name: pgadmin4
          image: dpage/pgadmin4:latest
          env:
           - name: PGADMIN_DEFAULT_EMAIL
             value: "test@ind.nl"
           - name: PGADMIN_DEFAULT_PASSWORD
             value: "test"
           - name: PGADMIN_PORT
             value: "80"
          ports:
            - containerPort: 80
              name: pgadminport
          securityContext:
            runAsUser: 0
            runAsGroup: 0
            allowPrivilegeEscalation: true
            readOnlyRootFilesystem: false
---
apiVersion: v1
kind: Service
metadata:
  name: pgadmin
  labels:
    app: pgadmin
spec:
  selector:
   app: pgadmin
  type: NodePort
  ports:
   - port: 80
     nodePort: 30200

故障复现与日志

  1. 首次使用root用户(runAsUser:0、runAsGroup:0)部署时,Pod输出权限错误:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted
sudo: PERM_SUDOERS: setresuid(-1, 1, -1): Operation not permitted
sudo: no valid sudoers sources found, quitting
sudo: error initializing audit plugin sudoers_audit
/entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted
/entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted
  1. 将runAsUser、runAsGroup修改为pgAdmin内置非root用户ID 5050后,Pod启动失败:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted
sudo: unable to change to root gid: Operation not permitted
sudo: error initializing audit plugin sudoers_audit
/entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted
/entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted
  1. 单独将runAsGroup改回0后,Pod依旧启动失败:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted
sudo: PERM_SUDOERS: setresuid(-1, 1, -1): Operation not permitted
sudo: no valid sudoers sources found, quitting
sudo: setresuid() [0, 0, 0] -> [5050, -1, -1]: Operation not permitted
sudo: error initializing audit plugin sudoers_audit
/entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted
/entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted

当前集群生效PSP配置

apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  annotations:
    psp.rke2.io/global-restricted: resolved
  creationTimestamp: "2022-06-30T14:00:25Z"
  name: global-restricted-psp
  resourceVersion: "3493795"
  uid: b7209f38-9609-4b81-b3ef-ab7a17b39bbd
spec:
  allowPrivilegeEscalation: true
  fsGroup:
    ranges:
    - max: 65535
      min: 0
    rule: MustRunAs
  requiredDropCapabilities:
  - ALL
  runAsUser:
    rule: RunAsAny
  seLinux:
    rule: RunAsAny
  supplementalGroups:
    ranges:
    - max: 65535
      min: 0
    rule: MustRunAs
  volumes:
  - configMap
  - emptyDir
  - projected
  - secret
  - downwardAPI
  - persistentVolumeClaim

根因定位

故障核心原因是PSP规则中配置了requiredDropCapabilities: ["ALL"],会强制丢弃容器所有Linux Capabilities。而dpage/pgadmin4官方镜像的默认启动脚本会调用sudo完成用户切换、目录权限修改等操作,这些操作依赖SETUID、SETGID两个Capability提供的系统调用权限,缺少对应权限时就会触发Operation not permitted错误,和runAsUser/runAsGroup的配置没有直接关系。

排查步骤

  1. 确认Pod实际绑定的PSP:执行kubectl get pod <pgadmin-pod名称> -o yaml | grep kubernetes.io/psp,确认生效策略为global-restricted-psp,排除其他PSP规则拦截的可能。
  2. 核对PSP规则:确认策略强制丢弃所有Capabilities,且没有针对pgAdmin工作负载的例外规则。
  3. 权限验证:临时使用特权模式启动pgAdmin镜像测试,确认服务可以正常启动,排除镜像本身损坏、配置错误的问题。

解决方案

方案1(最小权限,推荐过渡阶段使用)

不需要修改集群全局PSP规则,通过调整pgAdmin启动配置适配现有策略:

  • 使用pgAdmin镜像内置的非root用户(uid=5050,gid=5050)运行
  • 添加环境变量PGADMIN_DISABLE_SUDO: "1",跳过启动脚本中的sudo权限切换逻辑,直接以当前用户启动服务
  • 不需要额外添加Capabilities,完全符合现有PSP的安全规则
    对应修改后的容器配置片段:
containers:
  - name: pgadmin4
    image: dpage/pgadmin4:latest
    env:
     - name: PGADMIN_DEFAULT_EMAIL
       value: "test@ind.nl"
     - name: PGADMIN_DEFAULT_PASSWORD
       value: "test"
     - name: PGADMIN_PORT
       value: "80"
     - name: PGADMIN_DISABLE_SUDO
       value: "1"
    ports:
      - containerPort: 80
        name: pgadminport
    securityContext:
      runAsUser: 5050
      runAsGroup: 5050
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: false
      capabilities:
        drop:
          - ALL

方案2(兼容root启动逻辑)

如果需要保留root用户启动的逻辑,不需要修改全局PSP,只需要在容器securityContext中显式添加必须的Capabilities,覆盖PSP默认丢弃所有Capabilities的规则:

securityContext:
  runAsUser: 0
  runAsGroup: 0
  allowPrivilegeEscalation: true
  readOnlyRootFilesystem: false
  capabilities:
    drop:
      - ALL
    add:
      - SETUID
      - SETGID

内容的提问来源于stack exchange,提问作者Lucas Scheepers

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.28 01:54:22