Containers are processes on a shared Linux kernel, so how much privilege they run with matters. If an attacker exploits a bug in your app, a container running as root with a writable filesystem gives them far more to work with than one running as an unprivileged user with a read-only filesystem. The securityContext field lets you set these privileges declaratively.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.