adamant-kite-43734
07/24/2023, 4:32 PMeager-refrigerator-66976
07/24/2023, 4:37 PMeager-refrigerator-66976
07/24/2023, 6:19 PMeager-refrigerator-66976
07/24/2023, 6:20 PMapiVersion: <http://apiserver.config.k8s.io/v1|apiserver.config.k8s.io/v1>
kind: AdmissionConfiguration
plugins:
- name: PodSecurity
configuration:
apiVersion: <http://pod-security.admission.config.k8s.io/v1beta1|pod-security.admission.config.k8s.io/v1beta1>
kind: PodSecurityConfiguration
defaults:
enforce: "privileged"
enforce-version: "latest"
audit: "privileged"
audit-version: "latest"
warn: "privileged"
warn-version: "latest"
exemptions:
usernames: []
runtimeClasses: []
namespaces: []
nutritious-tomato-14686
07/24/2023, 8:54 PMeager-refrigerator-66976
07/24/2023, 8:55 PMeager-refrigerator-66976
07/24/2023, 8:56 PMdefaultPodSecurityAdmissionConfigurationTemplateName: rancher-privileged
and that workedeager-refrigerator-66976
07/24/2023, 8:56 PMnutritious-tomato-14686
07/24/2023, 8:56 PMnutritious-tomato-14686
07/24/2023, 8:57 PMeager-refrigerator-66976
07/24/2023, 8:57 PMeager-refrigerator-66976
07/24/2023, 8:58 PMnutritious-tomato-14686
07/24/2023, 8:58 PM--kube-apiserver-arg="admission-control-config-file=/var/lib/rancher/k3s/server/psa.yaml"
argument on startupnutritious-tomato-14686
07/24/2023, 8:59 PMeager-refrigerator-66976
07/24/2023, 9:00 PM--kube-apiserver-arg="admission-control-config-file=/var/lib/rancher/k3s/server/psa.yaml"
I’ve added it to try to force privileged
because I was assuming that k3s does restricted
by defaulteager-refrigerator-66976
07/24/2023, 9:01 PMnutritious-tomato-14686
07/24/2023, 9:01 PMeager-refrigerator-66976
07/24/2023, 9:02 PMnutritious-tomato-14686
07/24/2023, 9:02 PMcis
flag, you can find info about that here: https://docs.rke2.io/security/pod_security_standardseager-refrigerator-66976
07/24/2023, 9:03 PM