非root用户运行容器
设置运行的用户及用户组
不允许越权
这样不以root用户运行容器 安全一些
apiVersion: v1kind: Podmetadata:name: "myapp"spec:securityContext:runAsUser: 1000runAsGroup: 1000fsGroup: 2000volumes:- name: securityemptyDir: {}containers:- name: myappimage: busyboxcommand: ['sh','-c','sleep 1h']resources:limits:cpu: 200mmemory: 500Mirequests:cpu: 100mmemory: 200MivolumeMounts:- name: securitymountPath: /data/demosecurityContext:allowPrivilegeEscalation: false
将此pod跑起来之后就可以看到用户的变化
