Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because it would break all setuid binaries? Same reason the Linux kernel doesn't set no_new_privs (https://docs.kernel.org/userspace-api/no_new_privs.html) by default.

As an operator you are responsible for configuring your environment correctly. I would recommend starting here: https://kubernetes.io/docs/concepts/security/






Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: