Lộ trình
Cloud Native Computing FoundationAssociateTuần 3: Kiến trúc & bảo mậtBài 19 / 30

Ngày 19: SecurityContext

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
ckadngày 19
hoàn thành19 / 30 bài
Bối cảnh bài học

Thiết kế SecurityContext cho Pod/container: non-root identity, read-only root filesystem, capabilities, seccomp, writable mounts và debug permission failure.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Thiết kế SecurityContext cho Pod/container: non-root identity, read-only root filesystem, capabilities, seccomp, writable mounts và debug permission failure.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Thực hành cấu hình runAsNonRoot, readOnlyRootFilesystem
  • Học cách giới hạn Linux capabilities cho container
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Bật hardening có thể làm app fail vì UID không tồn tại, thư mục không writable hoặc capability bị drop; tắt security để app chạy lại thì mở attack surface. Bài học xây security contract rồi sửa permission tối thiểu.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • runAsUser/runAsGroup/runAsNonRoot, fsGroup và file ownership quyết định identity/process/volume access; image USER và Pod/container context có precedence cần kiểm tra.
  • readOnlyRootFilesystem giảm write surface nhưng app cần emptyDir/tmpfs hoặc writable volume có scope rõ cho runtime data.
  • Linux capabilities nên drop ALL rồi add tối thiểu theo syscall/feature cần thiết; privileged/allowPrivilegeEscalation/host namespaces có blast radius lớn.
  • seccompProfile RuntimeDefault/Localhost và Pod Security Admission policy tạo admission/runtime boundary; securityContext YAML cần verify effective behavior.

SecurityContext theo identity và write surface

Bắt đầu từ threat/requirement: UID/GID, volume ownership, writable paths, capabilities, seccomp và admission. runAsNonRoot không tự sửa quyền file; readOnlyRootFilesystem yêu cầu thiết kế /tmp/cache/data mount. Drop capability trước, add tối thiểu có lý do.

Debug mà không hạ hardening

Đọc admission/events/logs, exec id, kiểm tra mount/ownership/path và app behavior. PermissionDenied có thể do UID/fsGroup/read-only/capability; sửa đúng lớp. Tránh privileged, allowPrivilegeEscalation, host namespaces hoặc root như workaround mặc định.

Bài tập

Deploy hardened Pod, kiểm tra effective security, mô phỏng write/capability/UID/seccomp failure, sửa bằng mount/ownership/quyền tối thiểu và tạo variant. Cleanup labels/volumes và ghi exception nếu có.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
kubectl get pod -n ckad-day19 -o wide
kubectl describe pod POD_NAME -n ckad-day19
kubectl exec POD_NAME -n ckad-day19 -- id
kubectl exec POD_NAME -n ckad-day19 -- sh -c "touch /tmp/probe && touch /root/should-fail"
kubectl get pod POD_NAME -n ckad-day19 -o jsonpath="{.spec.securityContext} {.spec.containers[*].securityContext}{"\n"}"
kubectl get events -n ckad-day19 --sort-by=.lastTimestamp
Hands-on lab

Thực hành theo scenario

  1. Tạo namespace `ckad-day19`; triển khai app lab với runAsNonRoot, drop ALL, no privilege escalation, RuntimeDefault, readOnly rootfs và emptyDir `/tmp`; ghi expected uid/mount/capability.
  2. Verify bằng `get/describe`, logs, `exec id`, `mount`, writable/read-only path và Pod admission/conditions; kiểm tra Pod security labels/profile nếu cluster có.
  3. Cố ý làm app cần write root, port/feature cần capability hoặc image chạy root; thu PermissionDenied/admission/runtime evidence rồi sửa bằng writable mount, fsGroup/ownership hoặc capability tối thiểu.
  4. Tạo variant đổi UID/group/readOnly/capability/seccomp; compare attack surface và behavior. Không test privileged/hostPID/hostPath trên shared cluster.
  5. Cleanup Pod/namespace/security labels/volumes; ghi exception owner/expiry nếu hardening chưa hoàn toàn tương thích, không commit credential.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Effective identity/GID/ownership có evidence.
  • Read-only rootfs và writable paths đúng.
  • Capabilities/escalation/seccomp/privileged risk được phân biệt.
  • Permission failure sửa tối thiểu và có variant.
  • Admission/cleanup/exception safety rõ.
Transfer to exam / production

Bẫy thường gặp và trade-off

CKAD SecurityContext task hay cần đúng cấp Pod vs container. Kiểm tra `id`, mount và capability thực tế; nếu readOnlyRootFilesystem fail, thêm writable volume/path thay vì tắt hardening.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: App chạy non-root nhưng fail khi ghi cache vào `/app/cache` với readOnlyRootFilesystem. Remediation an toàn nhất là gì?

Kết thúc bài

Checklist trước khi sang Ngày 2