Skip to content

Start using hostUsers where possible #1748

@jcpunk

Description

@jcpunk

What would you like to be added:
Kubernetes 1.33+ offers user namespaces which further isolates users from the system and other pods on the same host.

Why is this needed:
While this runs as non-root, user namespace isolation would further isolate this from the rest of the system.

NOTE: kind doesn't support hostUsers: false

/kind feature

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/featureCategorizes issue or PR as related to a new feature.needs-triageIndicates an issue or PR lacks a `triage/foo` label and requires one.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    Needs Triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions