RKE2 Kubernetes集群部署pgAdmin因PSP问题致Pod崩溃如何解决
RKE2集群部署pgAdmin PSP权限故障排查与解决
问题背景
计划在RKE2 Kubernetes集群上部署pgAdmin用于数据库访问,当前pgAdmin Pod持续崩溃,初步判断为PSP(PodSecurityPolicy)相关问题。已知PSP已被废弃,团队后续计划切换至OPA作为策略引擎,需要在过渡阶段实现pgAdmin正常运行。
初始部署配置
使用如下Deployment与Service配置部署:
apiVersion: apps/v1 kind: Deployment metadata: name: pgadmin spec: selector: matchLabels: app: pgadmin replicas: 1 template: metadata: labels: app: pgadmin spec: containers: - name: pgadmin4 image: dpage/pgadmin4:latest env: - name: PGADMIN_DEFAULT_EMAIL value: "test@ind.nl" - name: PGADMIN_DEFAULT_PASSWORD value: "test" - name: PGADMIN_PORT value: "80" ports: - containerPort: 80 name: pgadminport securityContext: runAsUser: 0 runAsGroup: 0 allowPrivilegeEscalation: true readOnlyRootFilesystem: false --- apiVersion: v1 kind: Service metadata: name: pgadmin labels: app: pgadmin spec: selector: app: pgadmin type: NodePort ports: - port: 80 nodePort: 30200
故障复现与日志
- 首次使用root用户(runAsUser:0、runAsGroup:0)部署时,Pod输出权限错误:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted sudo: PERM_SUDOERS: setresuid(-1, 1, -1): Operation not permitted sudo: no valid sudoers sources found, quitting sudo: error initializing audit plugin sudoers_audit /entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted /entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted
- 将runAsUser、runAsGroup修改为pgAdmin内置非root用户ID 5050后,Pod启动失败:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted sudo: unable to change to root gid: Operation not permitted sudo: error initializing audit plugin sudoers_audit /entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted /entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted
- 单独将runAsGroup改回0后,Pod依旧启动失败:
/entrypoint.sh: line 62: /venv/bin/python3: Operation not permitted sudo: PERM_SUDOERS: setresuid(-1, 1, -1): Operation not permitted sudo: no valid sudoers sources found, quitting sudo: setresuid() [0, 0, 0] -> [5050, -1, -1]: Operation not permitted sudo: error initializing audit plugin sudoers_audit /entrypoint.sh: line 84: /venv/bin/python3: Operation not permitted /entrypoint.sh: exec: line 92: /venv/bin/gunicorn: Operation not permitted
当前集群生效PSP配置
apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: annotations: psp.rke2.io/global-restricted: resolved creationTimestamp: "2022-06-30T14:00:25Z" name: global-restricted-psp resourceVersion: "3493795" uid: b7209f38-9609-4b81-b3ef-ab7a17b39bbd spec: allowPrivilegeEscalation: true fsGroup: ranges: - max: 65535 min: 0 rule: MustRunAs requiredDropCapabilities: - ALL runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: ranges: - max: 65535 min: 0 rule: MustRunAs volumes: - configMap - emptyDir - projected - secret - downwardAPI - persistentVolumeClaim
根因定位
故障核心原因是PSP规则中配置了requiredDropCapabilities: ["ALL"],会强制丢弃容器所有Linux Capabilities。而dpage/pgadmin4官方镜像的默认启动脚本会调用sudo完成用户切换、目录权限修改等操作,这些操作依赖SETUID、SETGID两个Capability提供的系统调用权限,缺少对应权限时就会触发Operation not permitted错误,和runAsUser/runAsGroup的配置没有直接关系。
排查步骤
- 确认Pod实际绑定的PSP:执行
kubectl get pod <pgadmin-pod名称> -o yaml | grep kubernetes.io/psp,确认生效策略为global-restricted-psp,排除其他PSP规则拦截的可能。 - 核对PSP规则:确认策略强制丢弃所有Capabilities,且没有针对pgAdmin工作负载的例外规则。
- 权限验证:临时使用特权模式启动pgAdmin镜像测试,确认服务可以正常启动,排除镜像本身损坏、配置错误的问题。
解决方案
方案1(最小权限,推荐过渡阶段使用)
不需要修改集群全局PSP规则,通过调整pgAdmin启动配置适配现有策略:
- 使用pgAdmin镜像内置的非root用户(uid=5050,gid=5050)运行
- 添加环境变量
PGADMIN_DISABLE_SUDO: "1",跳过启动脚本中的sudo权限切换逻辑,直接以当前用户启动服务 - 不需要额外添加Capabilities,完全符合现有PSP的安全规则
对应修改后的容器配置片段:
containers: - name: pgadmin4 image: dpage/pgadmin4:latest env: - name: PGADMIN_DEFAULT_EMAIL value: "test@ind.nl" - name: PGADMIN_DEFAULT_PASSWORD value: "test" - name: PGADMIN_PORT value: "80" - name: PGADMIN_DISABLE_SUDO value: "1" ports: - containerPort: 80 name: pgadminport securityContext: runAsUser: 5050 runAsGroup: 5050 allowPrivilegeEscalation: false readOnlyRootFilesystem: false capabilities: drop: - ALL
方案2(兼容root启动逻辑)
如果需要保留root用户启动的逻辑,不需要修改全局PSP,只需要在容器securityContext中显式添加必须的Capabilities,覆盖PSP默认丢弃所有Capabilities的规则:
securityContext: runAsUser: 0 runAsGroup: 0 allowPrivilegeEscalation: true readOnlyRootFilesystem: false capabilities: drop: - ALL add: - SETUID - SETGID
内容的提问来源于stack exchange,提问作者Lucas Scheepers
相关产品推荐
相关产品推荐

