Pods在kubernetes

时间:2018-03-19 21:13:59

标签: docker kubernetes

我想将docker命令--user $(id -u):$(id -g)添加到我的k8s部署定义中。 k8s的等价物是什么?

args还是命令?

容器如何正常启动:

docker run -d -p 5901:5901 -p 6901:6901 --user $(id -u):$(id -g) khwhahn/daedalus:0.1

k8s deployment
apiVersion: extensions/v1beta1
kind: Deployment
metadata:
  annotations:
    kompose.cmd: kompose --file docker-compose.yaml convert
    kompose.version: 1.10.0 (8bb0907)
  creationTimestamp: null
  labels:
    io.kompose.service: daedalus
  name: daedalus
spec:
  replicas: 1
  strategy:
    type: Recreate
  template:
    metadata:
      creationTimestamp: null
      labels:
        io.kompose.service: daedalus
    spec:
      containers:
      - env:
        - name: DISPLAY
        image: khwhahn/daedalus:0.1
        imagePullPolicy: Always
        ports:
          - containerPort: 5901
            name: vnc
            protocol: TCP
          - containerPort: 6901
            name: http
            protocol: TCP
        livenessProbe:
            httpGet:
              path: /
              port: 6901
              scheme: HTTP
            initialDelaySeconds: 10
            timeoutSeconds: 1
            periodSeconds: 10
            successThreshold: 1
            failureThreshold: 3
        readinessProbe:
          httpGet:
            path: /
            port: 6901
            scheme: HTTP
          initialDelaySeconds: 10
          timeoutSeconds: 1
          periodSeconds: 10
          successThreshold: 1
          failureThreshold: 3
        name: daedalus
        resources: {}
        volumeMounts:
        - mountPath: /tmp/.X11-unix
          name: daedalus-claim0
        - mountPath: /home/daedalus/daedalus/tls
          name: cardano-tls
      restartPolicy: Always
      volumes:
      - name: daedalus-claim0
        persistentVolumeClaim:
          claimName: daedalus-claim0
      - name: cardano-tls
        persistentVolumeClaim:
          claimName: cardano-tls
status: {}

由于

1 个答案:

答案 0 :(得分:1)

最初在kubernetes issue 22179请求。

部分实施:

  

PodSecurityContext允许Kubernetes用户指定RunAsUser,可以在SecurityContext中基于每个Container重载RunAsUser。

     

在SecurityContext和PodSecurityContext中引入一个名为RunAsGroup的新API字段。

请参阅" Configure a Security Context for a Pod or Container"。