Closed dan-opitz closed 5 years ago
Issue Label Bot is not confident enough to auto-label this issue. See dashboard for more details.
container.seccomp.security.alpha.kubernetes.io/img: unconfined
?
What's your node distro and kernel?
Also make sure you are running the latest img
PSP on cluster doesn't allow seccomp
to be set apparently.
CentOS Linux 7 - 3.10.0-862.el7
Just tried pulling latest img and building from master with same result.
sudo sh -c "echo 28633 > /proc/sys/user/max_user_namespaces"
Hi, I have the same problem, if i ran your yaml example. The hint from AkihiroSuda helps if I run the docker example. But the hint from https://github.com/genuinetools/img#running-with-kubernetes , doesn't help. Or maybe you can give a little hint where to set "securityContext.privileged to true" exactly ? thx Christoph
feedback: I was able to run the yaml without any "privileged true" but I had to comment: -# securityContext: -# allowPrivilegeEscalation: false -# readOnlyRootFilesystem: true after that the "nsenter: failed to unshare namespaces: Invalid argument" disapeared... Hope it helps ....
I have the same problem in OKD 3.11. Any ideas? OKD is more security paranoid than Kubernetes.
UPD#1: Run this through with jenkins master, Kubernetes plugin. Used dynamic jenkins slaves.
@AkihiroSuda can you help me plz?)
I have seen other issues surrounding this but it sounded like a Mac problem originally so hoping to give a bit more info and see if there's a solution.
Kubernetes Server Version:
v1.12.4
Container Runtime Version:docker 18.6.3
I cloned
master
and ran adocker build
anddocker push
to my registry and then created a Pod spec with an initContainer to clone a repo to a volumeMount and then added theimg
container that referenced the cloned repo on the same volumeMount.I am unable to set
procMount: Unmasked
becauseUnamsked
is not allowed on the cluster at this time but I saw @AkihiroSuda mention this shouldn't be needed anymore.The
img
container fails with the following error:Any ideas or input on how to work around/solve this issue?
Example Yaml: