Open
Description
Enhancement Description
- One-line enhancement description (can be used as a release note): Add support for user namespaces in pods
- Kubernetes Enhancement Proposal: https://github.com/kubernetes/enhancements/blob/master/keps/sig-node/127-user-namespaces/README.md
- Discussion Link: This was discussed in several sig-node meetings, most notable Nov 2 2021 and in this PR, that feedback was incorporated already by this KEP is taking: keps/127: Support User Namespaces #2101.
- Primary contact (assignee): @rata @giuseppe
- Responsible SIGs: sig-node
- Enhancement target (which target equals to which milestone):
- Alpha release target (x.y): 1.25
- Beta1 release target (x.y): 1.30
- Beta2 release target (x.y): 1.33
- Stable release target (x.y):
- Alpha
- KEP (
k/enhancements
) update PR(s):- v1.24 127: Add KEP for user namespaces support #3065
- v1.25 KEP-127: Mark as implementable (target phase I for 1.25) #3275
- v1.27 KEP-127: Support userns in stateless pods with idmap mounts #3811
- v1.28 [KEP-127] Add Pod Security Standards to User Namespaces KEP #4044
- v1.28 KEP-127: add support for stateful pods #4084
- v1.28 KEP-127: Fix user namespaces feature gate name #4107
- v1.28 KEP-127: Update feature gate name and update last-milestone for 1.29 #4147
- Code (
k/k
) update PR(s): - Docs (
k/website
) update PR(s):
- KEP (
- Beta 1 (default off)
- KEP (
k/enhancements
) update PR(s): - Code (
k/k
) update PR(s): - Docs (
k/website
) update(s):
- KEP (
- Beta 2 (default on)
- KEP (
k/enhancements
) update PR(s): - Code PRs for 1.33:
- features: Enable user namespaces by default kubernetes#130138
- kubelet: config: add userNamespaces.idsPerPod kubernetes#130028
- Revert userns kernel check kubernetes#130243
- Userns: Add e2e tests for custom kubelet mappings, skip on windows and minor improvements kubernetes#130726
- Fix unit tests on windows kubernetes#130800
- userns: Don't special-case windows for the kubelet userns mappings kubernetes#130820.
- Doc PR for 1.33:
- KEP (
Please keep this description up to date. This will help the Enhancement Team to track the evolution of the enhancement efficiently.
Metadata
Metadata
Labels
Categorizes issue or PR as related to adding, removing, or otherwise changing an APICategorizes issue or PR as related to a new feature.Denotes that an issue has been opted in to a releaseCategorizes an issue or PR as relevant to SIG Node.Denotes an issue tracking an enhancement targeted for Beta statusDenotes an enhancement issue is actively being tracked by the Release Team
Type
Projects
Status
Tracked for enhancements freeze
Status
Tracked