Skip to content

Container privileges

In Kubernetes, you can run vScope with three levels of privileges. Use the recommended setup unless your cluster policies require restricted privileges. The choice affects what discovery can do.

The vScope image runs as root inside the container by default. vScope then has the permissions its probes need, and discovery works the same as on a Linux server. This is the setup used in the Installation guide.

vScope still runs as root inside the container, but Kubernetes maps that user to an unprivileged user on the node. Discovery works the same as with root. Use this when your cluster policies require user namespaces or do not allow containers to run as root on the node. This requires a recent cluster; see System Requirements.

vScope runs as a regular user. Use this when your cluster policies require non-root containers. Some discovery functions are limited:

  • Raw sockets are not available, so ping discovery cannot use raw ICMP. vScope falls back to other methods to find hosts.
  • Other probes that need elevated privileges may run into permission problems, for example remote PowerShell.

To set up either alternative, see Run vScope in Kubernetes with restricted privileges.