← all discussions

User namespaces for pods: anyone running hostUsers: false in production?

nunullroute1 day ago2 replies

Setting hostUsers: false maps root inside the container to an unprivileged UID on the host. On paper it removes a whole class of container escape impact. What breaks?

Discussion

sesecops_jules20 hours ago

Volumes. Anything that needs specific file ownership on the host side gets confusing fast. idmap mounts help but need filesystem support — check your runtime and kernel.

Reply
nunullroute18 hours ago

Makes sense. So stateless first, then work up.

Reply