Navigation Menu

Skip to content

Instantly share code, notes, and snippets.

@fkautz
Last active August 1, 2018 18:19
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save fkautz/1b0f5c545d0995b5274f997da3fe72f6 to your computer and use it in GitHub Desktop.
Save fkautz/1b0f5c545d0995b5274f997da3fe72f6 to your computer and use it in GitHub Desktop.
binding privileged container to netns of unprivileged container
$ kubectl get pods
NAME                      READY     STATUS        RESTARTS   AGE
nginx-56f766d96f-lxkc9    1/1       Running       0          6m
$ docker ps | grep k8s_POD_nginx-56f766d96f-lxkc9
85b59aced967        k8s.gcr.io/pause-amd64:3.1   "/pause"                 7 minutes ago       Up 7 minutes                            k8s_POD_nginx-56f766d96f-lxkc9_default_426a6401-95b5-11e8-8a83-0800271b7911_0
$ docker run -i -t --privileged --net=container:85b59aced967 alpine /bin/sh
$ apk update
$ apk add libcap-ng-utils
$ pscap -a
ppid  pid   name        command           capabilities
0     1     root        sh                full
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment