1. Checking the User Running the Sleep Process in the Ubuntu Sleeper Pod
To verify which user is running the sleep process in your Ubuntu sleeper pod, follow these steps:- List the running pods to identify the pod name.
- Execute the command inside the pod using the
whoamicommand to check the current user.
If you see
root as the output, it indicates that no user override has been set, and the container is running with root privileges.2. Updating the Ubuntu Sleeper Pod to Run with User ID 1010
To update the pod so that the sleep process is executed as user ID 1010, proceed as follows:-
Retrieve the current pod configuration and write it to a file:
-
Open the
ubuntu-sleeper.yamlfile in your preferred text editor. -
Locate the
securityContextsection and add or update therunAsUserfield to1010. - Save your changes.
-
Delete the existing pod. Using the
--forceflag can expedite deletion: -
Reapply the modified configuration file:
3. Analyzing a Multi-Container Pod Definition
Consider a pod definition file namedmulti-pod.yaml that includes multiple containers with different security contexts set at the pod and container levels. Below is the configuration snippet:
Q1: With which user does the web container run?
- The pod-level context sets
runAsUser: 1001, but the web container’s own security context overrides this withrunAsUser: 1002. - Answer: The web container runs as user 1002.
Q2: With which user does the sidecar container run?
- The sidecar container does not have a specified security context. It inherits the pod-level setting.
- Answer: The sidecar container runs as user 1001.
4. Configuring the Ubuntu Sleeper Pod to Run as Root with SYS_TIME Capability
To update the Ubuntu sleeper pod so that it runs as root with the additionalSYS_TIME capability, follow these instructions:
- Open the existing configuration file (
ubuntu-sleeper.yaml). - Remove any lines in the security context that force the pod to run as a non-root user.
- Add a container-level security context that specifies the
SYS_TIMEcapability. Your updated configuration should resemble the following:
- Save the changes.
-
Delete the existing pod using:
-
Reapply the updated configuration:
SYS_TIME capability as expected.
5. Adding the NET_ADMIN Capability to the Ubuntu Sleeper Pod
To enhance the Ubuntu sleeper pod so that it includes both theSYS_TIME and NET_ADMIN capabilities, update the configuration file as follows:
- Open the
ubuntu-sleeper.yamlfile. - Locate the container’s
securityContextsection that defines the capabilities. - Modify the capabilities to include both
SYS_TIMEandNET_ADMIN:
- Save the file.
-
Delete the current pod:
-
Apply the new configuration:
SYS_TIME and NET_ADMIN capabilities enabled.
You have now successfully adjusted the security contexts for your Ubuntu sleeper pod. This guide covered verifying container users, configuring pods to run with specific user IDs, and modifying container capabilities to enhance security.