OpenShift 4.6是否需自定义SCC覆盖seccomp、allowPrivilegeEscalation等参数
问题结论
你需要自定义SecurityContextConstraints(SCC)才能让配置生效,核心原因是OpenShift的SCC是集群级强制准入规则,Pod配置无法突破匹配到的SCC的限制。
问题根因
- OpenShift 4.6版本的默认
restrictedSCC默认未放开RuntimeDefault类型的seccompProfile使用权限,你在Deployment中添加seccompProfile: RuntimeDefault配置后,Pod无法匹配到默认restrictedSCC,会自动匹配优先级更高、权限更大的其他SCC。 - 权限更高的SCC默认
allowPrivilegeEscalation配置为true,SCC的规则优先级高于Deployment中定义的securityContext配置,因此你手动设置的allowPrivilegeEscalation: false会被直接覆盖。
解决步骤
- 导出默认restricted SCC的配置作为自定义SCC的基础:
oc get scc restricted -o yaml > custom-restricted-scc.yaml
- 修改配置文件,调整以下参数:
- 修改
metadata.name为自定义名称,比如custom-restricted-seccomp - 在
seccompProfiles字段中添加RuntimeDefault,放开该seccomp类型的使用权限 - 将
allowPrivilegeEscalation设置为false,强制匹配该SCC的Pod禁用特权提升
- 创建自定义SCC:
oc apply -f custom-restricted-scc.yaml
- 将自定义SCC绑定到你的Deployment对应的ServiceAccount:
oc adm policy add-scc-to-user custom-restricted-seccomp -z <你的ServiceAccount名称>
配置完成后重新部署 workload 即可生效。
内容的提问来源于stack exchange,提问作者zyriuse
相关产品推荐
相关产品推荐

