If tool.X is running a pod with a few containers, they should all run with the uid of tool.X. This should be enforced via an admission controller.
Description
Description
| Status | Subtype | Assigned | Task | ||
|---|---|---|---|---|---|
| Resolved | yuvipanda | T111885 Initial Deployment of Kubernetes to Tool Labs | |||
| Resolved | yuvipanda | T116504 Enforce that containers from a user run with the uid assigned to that user |
Event Timeline
Comment Actions
https://github.com/kubernetes/kubernetes/pull/16250 has discussions, not going very well atm unfortunately :(
Comment Actions
Wheee! See pull request in previous comment for details, but we have this deployed in our cluster now. Need to test it and throw stuff at it to make sure it's rock solid...