Skip to content

Run as nonRoot and set automountServiceAccountToken to false #694

@ethan-young-vgm

Description

@ethan-young-vgm

We have implemented GPU Operator on our AKS cluster, and it is working great.
Few issues though. Azure is lighting up with high security vulnerabilities due to running the containers as root and auto mounting the service account token to the container.

We have already fixed these issues for everything else and even had to switch Kafka helm chart providers...
I don't see an option in GPU Operator's helm chart to configure these two settings.

I know this is not just on AKS as I saw others from other cloud providers saying the same with other helm charts, so my question is, will this be added in the future or is this even something that can be done with GPU Operator?

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionCategorizes issue or PR as a support question.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions