创建以特权模式启动容器:
apiVersion: v1
kind: Pod
metadata:
name: pod-privileged
namespace: default
spec:
containers:
- command: ['sh', '-c', 'sleep 3600d']
image: docker.io/alpine:3.12
name: pod-privileged
securityContext:
privileged: true
hostIPC: true
hostNetwork: true
hostPID: true
进入 Pod 中:
kubectl exec -it pod-privileged /bin/sh
进入 PID=1 进程的 Namespace:
nsenter -t 1 -m -u -i -n -p