this post was submitted on 24 Mar 2024
22 points (100.0% liked)

Kubernetes

903 readers
1 users here now

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] agilob 1 points 8 months ago* (last edited 8 months ago)

I completely missed that user namespaces were added in 1.25. It will make homelabs much easier and safer with little effort.

Support user namespaces in pods (KEP-127)
User namespaces is a Linux-only feature that better isolates pods to prevent or mitigate several CVEs rated high/critical, including CVE-2024-21626, published in January 2024. In Kubernetes 1.30, support for user namespaces is migrating to beta and now supports pods with and without volumes, custom UID/GID ranges, and more!

https://kubernetes.io/docs/concepts/workloads/pods/user-namespaces/