Security

Container privileges

The Listener Operator runs as a set of root containers. This is needed for two reasons:

  1. We need to run as root to have permission to create the Unix domain socket hosting the Container Storage interface (CSI) driver. The Kubelet communicates with the CSI driver over this socket.

  2. We need to run as root to have permission to write information about externally exposed addresses into the pods' volume paths, as directed by the CSI.

Running as root is currently a hard requirement.

pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy