You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift 4.6是否需自定义SCC覆盖seccomp、allowPrivilegeEscalation等参数

问题结论

你需要自定义SecurityContextConstraints(SCC)才能让配置生效,核心原因是OpenShift的SCC是集群级强制准入规则,Pod配置无法突破匹配到的SCC的限制。

问题根因

  1. OpenShift 4.6版本的默认restricted SCC默认未放开RuntimeDefault类型的seccompProfile使用权限,你在Deployment中添加seccompProfile: RuntimeDefault配置后,Pod无法匹配到默认restricted SCC,会自动匹配优先级更高、权限更大的其他SCC。
  2. 权限更高的SCC默认allowPrivilegeEscalation配置为true,SCC的规则优先级高于Deployment中定义的securityContext配置,因此你手动设置的allowPrivilegeEscalation: false会被直接覆盖。

解决步骤

  1. 导出默认restricted SCC的配置作为自定义SCC的基础:
oc get scc restricted -o yaml > custom-restricted-scc.yaml
  1. 修改配置文件,调整以下参数:
  • 修改metadata.name为自定义名称,比如custom-restricted-seccomp
  • 在seccompProfiles字段中添加RuntimeDefault,放开该seccomp类型的使用权限
  • 将allowPrivilegeEscalation设置为false,强制匹配该SCC的Pod禁用特权提升
  1. 创建自定义SCC:
oc apply -f custom-restricted-scc.yaml
  1. 将自定义SCC绑定到你的Deployment对应的ServiceAccount:
oc adm policy add-scc-to-user custom-restricted-seccomp -z <你的ServiceAccount名称>

配置完成后重新部署 workload 即可生效。


内容的提问来源于stack exchange,提问作者zyriuse

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.23 20:45:02