Ch. 14 · Kubernetes

Kubernetes Security Contexts and Runtime Permissions

Kubernetes Security Contexts and Runtime Permissions. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readadvancedupdated Oct 3, 2026

Security contexts specify runtime privileges and restrictions. Pair them with image permissions and the workload’s actual needs.

Before you start

You should understand Pods, Deployments and Services. Read desired configuration separately from observed cluster state. Use a development cluster when trying changes, and inspect events and status rather than assuming that an accepted manifest means the workload is ready to serve traffic.

The practical goal is to reason through this situation: Run as a nonroot user with a read-only filesystem and narrow writable volumes. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Inventory actual privileges

List operations requiring users, capabilities and writable paths.

Step 2: Remove unnecessary access

Run nonroot and narrow capabilities and mounts where viable.

Step 3: Test restricted execution

Include startup and failure behavior, not only a simple health response.

Worked scenario

Run as a nonroot user with a read-only filesystem and narrow writable volumes.

A service reads configuration and writes uploads to a mounted directory. It does not need privileged mode or a writable application root. Restricting it exposes hidden writes from a library; provide a specific scratch path instead of restoring broad privileges without understanding that requirement.

Common mistake

Applying restrictions without testing can break startup or hidden runtime writes.

Verify the behavior

Exercise uploads, startup, temporary files and diagnostic paths under the restrictions.

Interview exercise

Reduce privileges safely.

Answer and reasoning

Inventory required operations, remove unnecessary capabilities and verify both normal and failure paths under the restrictions.

Continue learning

Compare the scenario with the Kubernetes interview questions and test your understanding with the Kubernetes MCQs. For terminology and implementation details, consult the reference material.

More in Kubernetes

read ✓Kubernetes · hard

Kubernetes Pod Security Admission

Enforce pod hardening with the Pod Security Admission levels, and migrate workloads off the removed PodSecurityPolicy.

~2 min readread →
read ✓Kubernetes · mid

Kubernetes ConfigMap Update Behavior

Understand why ConfigMap changes reach volumes but not environment variables, and how to roll a Deployment deliberately.

~2 min readread →
read ✓Kubernetes · mid

Kubernetes emptyDir Volumes

Share scratch space between containers in a pod with emptyDir, choose the backing medium, and bound its size.

~2 min readread →
esc