SecurityContext theo identity và write surface
Bắt đầu từ threat/requirement: UID/GID, volume ownership, writable paths, capabilities, seccomp và admission. runAsNonRoot không tự sửa quyền file; readOnlyRootFilesystem yêu cầu thiết kế /tmp/cache/data mount. Drop capability trước, add tối thiểu có lý do.
Debug mà không hạ hardening
Đọc admission/events/logs, exec id, kiểm tra mount/ownership/path và app behavior. PermissionDenied có thể do UID/fsGroup/read-only/capability; sửa đúng lớp. Tránh privileged, allowPrivilegeEscalation, host namespaces hoặc root như workaround mặc định.
Bài tập
Deploy hardened Pod, kiểm tra effective security, mô phỏng write/capability/UID/seccomp failure, sửa bằng mount/ownership/quyền tối thiểu và tạo variant. Cleanup labels/volumes và ghi exception nếu có.