In example unit file, run the scheduler as kube, not root
Only the kubelet and proxy do things which need root privs
This commit is contained in:
@@ -6,6 +6,7 @@ Documentation=https://github.com/GoogleCloudPlatform/kubernetes
|
|||||||
EnvironmentFile=-/etc/kubernetes/config
|
EnvironmentFile=-/etc/kubernetes/config
|
||||||
EnvironmentFile=-/etc/kubernetes/apiserver
|
EnvironmentFile=-/etc/kubernetes/apiserver
|
||||||
EnvironmentFile=-/etc/kubernetes/scheduler
|
EnvironmentFile=-/etc/kubernetes/scheduler
|
||||||
|
User=kube
|
||||||
ExecStart=/usr/bin/kube-scheduler \
|
ExecStart=/usr/bin/kube-scheduler \
|
||||||
${KUBE_LOGTOSTDERR} \
|
${KUBE_LOGTOSTDERR} \
|
||||||
${KUBE_LOG_LEVEL} \
|
${KUBE_LOG_LEVEL} \
|
||||||
|
Reference in New Issue
Block a user