Security contexts specify runtime privileges and restrictions. Pair them with image permissions and the workload’s actual needs.
Before you start
You should understand Pods, Deployments and Services. Read desired configuration separately from observed cluster state. Use a development cluster when trying changes, and inspect events and status rather than assuming that an accepted manifest means the workload is ready to serve traffic.
The practical goal is to reason through this situation: Run as a nonroot user with a read-only filesystem and narrow writable volumes. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Inventory actual privileges
List operations requiring users, capabilities and writable paths.
Step 2: Remove unnecessary access
Run nonroot and narrow capabilities and mounts where viable.
Step 3: Test restricted execution
Include startup and failure behavior, not only a simple health response.
Worked scenario
Run as a nonroot user with a read-only filesystem and narrow writable volumes.
A service reads configuration and writes uploads to a mounted directory. It does not need privileged mode or a writable application root. Restricting it exposes hidden writes from a library; provide a specific scratch path instead of restoring broad privileges without understanding that requirement.
Common mistake
Applying restrictions without testing can break startup or hidden runtime writes.
Verify the behavior
Exercise uploads, startup, temporary files and diagnostic paths under the restrictions.
Interview exercise
Reduce privileges safely.
Answer and reasoning
Inventory required operations, remove unnecessary capabilities and verify both normal and failure paths under the restrictions.
Continue learning
Compare the scenario with the Kubernetes interview questions and test your understanding with the Kubernetes MCQs. For terminology and implementation details, consult the reference material.