Privileged containers weaken the host boundary
Running a container as privileged effectively removes the separation it was providing.
It is done to make something work: a tool that needs device access, an agent that needs to see the host. Each instance is justified and the result is a workload that can reach the host directly. The question is always whether a narrower capability would do, and usually one would.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- A pod service account is an identityA badge on the same rail
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Admission control can stop risky objects before they runStopped on the chute
- Mutable image tags can move underneath youSame ticket, different coat
