問題文
A namespace enforces the restricted Pod Security Standard. A team submits a Pod whose containers do not mention capabilities at all, and the Pod is rejected. Which requirement of that profile accounts for the rejection?
選択肢
- Containers must run as user ID 0 and the profile can drop privileges itself once the container has started.
- Containers may add whichever capability they need as long as they also declare a seccomp profile of type RuntimeDefault and that profile constrains which system calls are reachable.
- Containers must declare a hostPort and the profile can verify the exposure that the workload asks for.
- Containers must drop ALL capabilities, and may only add back NET_BIND_SERVICE.