Pod user namespaces

파드 사용자 네임스페이스

Map container user IDs to different, unprivileged host IDs.

···
html
<div class="stage" data-phase="0"><div class="title">USER ID MAPPING</div><div class="row mapping"><div class="panel">CONTAINER<br><b>root · UID 0</b></div><div class="boundary">→</div><div class="panel">HOST<br><b class="mapped">UID ?</b></div></div><div class="sub">same process, different host identity</div></div>
css
.stage{width:min(94vw,760px);height:min(88vh,330px);padding:clamp(9px,2.6vmin,20px);border:1px solid var(--line);border-radius:14px;background:var(--surface);font:600 clamp(12px,2.5vmin,16px)/1.3 "Pretendard Variable",Pretendard,-apple-system,BlinkMacSystemFont,"Apple SD Gothic Neo",sans-serif;display:flex;flex-direction:column;gap:clamp(6px,1.7vmin,12px);overflow:hidden;position:relative}.stage *{min-width:0}.stage .title{color:var(--accent);font-weight:800}.stage .sub{color:var(--muted)}.stage .row{display:flex;align-items:center;gap:clamp(5px,1.6vmin,12px)}.stage .panel{border:1px solid var(--line);border-radius:8px;background:var(--bg);padding:clamp(6px,1.6vmin,12px)}.stage .mono{font-family:ui-monospace,SFMono-Regular,monospace;font-size:clamp(12px,2.5vmin,15px)}.stage .grow{flex:1}.stage .on{color:var(--accent)}.mapping{flex:1;justify-content:center}.mapping .panel{width:39%;text-align:center}.mapping b{display:block;color:var(--accent);margin-top:9px}.boundary{height:65%;border-left:3px dashed var(--accent-3);display:grid;place-items:center;padding:0 10px;font-size:clamp(22px,5vmin,38px)}.stage[data-phase="1"] .boundary{border-color:var(--accent);color:var(--accent)}.stage[data-phase="2"] .mapped{font-size:0}.stage[data-phase="2"] .mapped:after{content:'UID 100000';font-size:clamp(12px,2.5vmin,16px)}.stage[data-phase="2"] .mapping .panel:last-child{border-color:var(--accent);background:color-mix(in srgb,var(--accent) 15%,var(--surface))}
js
const stage=document.querySelector('.stage');let phase=0;function advance(){phase=(phase+1)%3;stage.dataset.phase=String(phase)}const timer=setInterval(advance,1200);stage.addEventListener('pointerdown',()=>{clearInterval(timer);advance()})

With pod user namespaces, root inside a container can map to an unprivileged UID on the host. That adds a layer of isolation if a container boundary fails.

The demo maps container UID 0 to a separate host UID. Support is stable in Kubernetes 1.36, while volume and runtime compatibility should be checked in the target environment.

When to use

Use it when reducing the host impact of container privileges.

Open as page ↗