真题解析
Last updated
Last updated
# vim gVisorRuntimeClass.yaml
apiVersion: node.k8s.io/v1
kind: RuntimeClass
metadata:
# 用来引用 RuntimeClass 的名字
# RuntimeClass 是一个集群层面的资源
name: untrusted
# 对应的 CRI 配置的名称
handler: runsc
kubectl create -f gVisorRuntimeClass.yamlkubectl get pod nginx -n client -o yaml > nginx.yaml
vim nginx.yaml
apiVersion: v1
kind: Pod
metadata:
labels:
run: nginx
name: nginx
namespace: client
spec:
runtimeClassName: untrusted # 添加此项配置
containers:
- image: nginx
imagePullPolicy: Always
name: nginx
resources: {}
kubectl delete -f nginx.yaml
kubectl create -f nginx.yaml