mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-06-28 08:17:37 +00:00
docs: Clarify security boundaries in privileged mode
See https://github.com/kata-containers/runtime/issues/1568 Fixes #453 Signed-off-by: Leopold Schabel <mail@leoschabel.de>
This commit is contained in:
parent
adc0462a88
commit
0721b6a2e9
@ -221,11 +221,15 @@ See more documentation at
|
||||
|
||||
Privileged support in Kata is essentially different from `runc` containers.
|
||||
Kata does support `docker run --privileged` command, but in this case full access
|
||||
to the guest VM is provided instead of the host.
|
||||
to the guest VM is provided in addition to some host access.
|
||||
|
||||
The container runs with elevated capabilities within the guest and is granted
|
||||
access to guest devices instead of the host devices.
|
||||
This is also true with using `securityContext privileged=true` with Kubernetes.
|
||||
|
||||
The container may also be granted full access to a subset of host devices
|
||||
(https://github.com/kata-containers/runtime/issues/1568).
|
||||
|
||||
# Miscellaneous
|
||||
|
||||
This section lists limitations where the possible solutions are uncertain.
|
||||
|
Loading…
Reference in New Issue
Block a user