-
-
Notifications
You must be signed in to change notification settings - Fork 967
Open
Description
This is in a deployment with KIND:
kubectl apply -f scenarios/docker-bench-security/deployment.yaml
kubectl get pods -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
batch-check-job-mv8kk 1/1 Running 0 2d 10.244.231.215 kubernetes-worker <none> <none>
build-code-deployment-6b6546cdbc-9qc28 1/1 Running 3 (46h ago) 11d 10.244.231.218 kubernetes-worker <none> <none>
docker-bench-security-9rkqh 0/1 ContainerCreating 0 3m22s
Stuck on ContainerCreating after 1 hour...
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal Scheduled 3m11s default-scheduler Successfully assigned default/docker-bench-security-dmhbq to kubernetes-worker
Warning FailedMount 64s (x9 over 3m12s) kubelet MountVolume.SetUp failed for volume "docker-sock-volume" : hostPath type check failed: /var/run/docker.sock is not a directory
Need to go back to type: Socket here to make it work in KIND:
volumes:
- name: docker-sock-volume
hostPath:
path: /var/run/docker.sock
type: Socket
root@kubernetes-master:~/kubernetes-goat/scenarios/docker-bench-security# kubectl get pods -o wide
NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES
batch-check-job-mv8kk 1/1 Running 0 2d1h 10.244.231.215 kubernetes-worker <none> <none>
build-code-deployment-6b6546cdbc-9qc28 1/1 Running 3 (46h ago) 11d 10.244.231.218 kubernetes-worker <none> <none>
docker-bench-security-k45r6 1/1 Running 0 117s 192.168.183.201 kubernetes-worker <none> <none>
Events:
Type Reason Age From Message
---- ------ ---- ---- -------
Normal Scheduled 13m default-scheduler Successfully assigned default/docker-bench-security-k45r6 to kubernetes-worker
Normal Pulling 13m kubelet Pulling image "madhuakula/hacker-container"
Normal Pulled 11m kubelet Successfully pulled image "madhuakula/hacker-container" in 1m29.796s (1m29.796s including waiting). Image size: 444025991 bytes.
Normal Created 11m kubelet Created container: docker-bench
Normal Started 11m kubelet Started container docker-bench
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels