Container privileges
In Kubernetes, you can run vScope with three levels of privileges. Use the recommended setup unless your cluster policies require restricted privileges. The choice affects what discovery can do.
Root (recommended)
Section titled “Root (recommended)”The vScope image runs as root inside the container by default. vScope then has the permissions its probes need, and discovery works the same as on a Linux server. This is the setup used in the Installation guide.
User namespace
Section titled “User namespace”vScope still runs as root inside the container, but Kubernetes maps that user to an unprivileged user on the node. Discovery works the same as with root. Use this when your cluster policies require user namespaces or do not allow containers to run as root on the node. This requires a recent cluster; see System Requirements.
Non-root
Section titled “Non-root”vScope runs as a regular user. Use this when your cluster policies require non-root containers. Some discovery functions are limited:
- Raw sockets are not available, so ping discovery cannot use raw ICMP. vScope falls back to other methods to find hosts.
- Other probes that need elevated privileges may run into permission problems, for example remote PowerShell.
To set up either alternative, see Run vScope in Kubernetes with restricted privileges.