Replies: 2 comments 3 replies
-
|
@haircommander please see |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Ref: https://kubernetes.io/docs/tasks/configure-pod-container/security-context/ |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Docker provides a feature to ensure that by default all new containers are restricted from acquiring new privileges.
To do so, we need to set it like:
You should ensure that the --no-new-privileges parameter is present and that it is not set to false.
The contents of /etc/docker/daemon.json should also be reviewed.
Is there some similar feature in CRI-O as well?
If no, why do you feel, it is not required in CRI-O?
Beta Was this translation helpful? Give feedback.
All reactions