Open vishnukarthikl opened 4 weeks ago
You would have to inject both /proc/driver/nvidia/capabilities/mig/monitor and /dev/nvidia-caps/nvidia-cap1
Though you may not be able to mount the /proc
stuff directly (which shouldn't strictly be necessary). Try it with just the device node.
Hello all, I am evaluating whether the device plugin can be run without SYS_ADMIN capabilities for mixed mode MIG. Currently the capability is needed to query the MIG slice's memory info. But this also increases the security surface area of the Pod and I am considering if we can reduce it.
Based on @klueska comment, it seems possible to pass the capabilities directly into the container without having to explicitly add
SYS_ADMIN
. I tried to bind mount the host's/proc/driver/nvidia/capabilities/mig/monitor
into container but running into pod error. Using a build fromrelease-0.13
Has anyone made this working? Any examples would definitely help.
Thanks