StudyToCert

All certifications / CKAD / Lessons

Certified Kubernetes Application Developer CKAD (Kubernetes v1.35 curriculum) · Domain 4: Application Environment, Configuration and Security

SecurityContext at Pod and container level: runAsUser, runAsNonRoot, fsGroup, readOnlyRootFilesystem, allowPrivilegeEscalation

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Containers are processes on a shared Linux kernel, so how much privilege they run with matters. If an attacker exploits a bug in your app, a container running as root with a writable filesystem gives them far more to work with than one running as an unprivileged user with a read-only filesystem. The securityContext field lets you set these privileges declaratively.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CKAD for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKAD study plan