未验证 提交 40d7633a 编写于 作者: T Thomas Strömberg 提交者: GitHub

Merge pull request #7149 from laozc/nvidia-gpu-sec

Do not run GPU plugin under priviledge mode
......@@ -42,9 +42,6 @@ spec:
- name: device-plugin
hostPath:
path: /var/lib/kubelet/device-plugins
- name: dev
hostPath:
path: /dev
containers:
- image: "nvidia/k8s-device-plugin:1.0.0-beta4"
command: ["/usr/bin/nvidia-device-plugin", "-logtostderr"]
......@@ -54,11 +51,11 @@ spec:
cpu: 50m
memory: 10Mi
securityContext:
privileged: true
allowPrivilegeEscalation: false
capabilities:
drop: ["ALL"]
volumeMounts:
- name: device-plugin
mountPath: /var/lib/kubelet/device-plugins
- name: dev
mountPath: /dev
updateStrategy:
type: RollingUpdate
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册