Open
Description
There is a thread going on in k8s KEP regarding subtle and inconsistent behaviors between runAsGroup
and supplementalGroups
.
@thockin summarizes here: kubernetes/enhancements#3620 (comment)
It sounds like runtime-spec and runc may currently be inconsistent/broken, but to "fix" it would be potentially a breaking change.
cc @opencontainers/runtime-spec-maintainers
Metadata
Metadata
Assignees
Labels
No labels