Merge pull request #40376 from dtzar/patch-1
clarify Windows privileged containers feature enablement
This commit is contained in:
		
						commit
						eb7c049f04
					
				| 
						 | 
				
			
			@ -57,7 +57,7 @@ fail validation.
 | 
			
		|||
		<tr>
 | 
			
		||||
			<td style="white-space: nowrap">HostProcess</td>
 | 
			
		||||
			<td>
 | 
			
		||||
				<p>Windows pods offer the ability to run <a href="/docs/tasks/configure-pod-container/create-hostprocess-pod">HostProcess containers</a> which enables privileged access to the Windows node. Privileged access to the host is disallowed in the baseline policy. {{< feature-state for_k8s_version="v1.23" state="beta" >}}</p>
 | 
			
		||||
				<p>Windows pods offer the ability to run <a href="/docs/tasks/configure-pod-container/create-hostprocess-pod">HostProcess containers</a> which enables privileged access to the Windows node. Privileged access to the host is disallowed in the baseline policy. {{< feature-state for_k8s_version="v1.26" state="stable" >}}</p>
 | 
			
		||||
				<p><strong>Restricted Fields</strong></p>
 | 
			
		||||
				<ul>
 | 
			
		||||
					<li><code>spec.securityContext.windowsOptions.hostProcess</code></li>
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
| 
						 | 
				
			
			@ -307,12 +307,10 @@ capabilities such as manipulating the network stack or accessing hardware device
 | 
			
		|||
 | 
			
		||||
{{< feature-state for_k8s_version="v1.26" state="stable" >}}
 | 
			
		||||
 | 
			
		||||
In Windows, you can create a [Windows HostProcess pod](/docs/tasks/configure-pod-container/create-hostprocess-pod)
 | 
			
		||||
by setting the `windowsOptions.hostProcess` flag on the security context of the pod spec. All containers in these
 | 
			
		||||
In Windows, you can create a [Windows HostProcess pod](/docs/tasks/configure-pod-container/create-hostprocess-pod) by setting the 
 | 
			
		||||
`windowsOptions.hostProcess` flag on the security context of the pod spec. All containers in these
 | 
			
		||||
pods must run as Windows HostProcess containers. HostProcess pods run directly on the host and can also be used
 | 
			
		||||
to perform administrative tasks as is done with Linux privileged containers. In order to use this feature, the
 | 
			
		||||
`WindowsHostProcessContainers` [feature gate](/docs/reference/command-line-tools-reference/feature-gates/) must be enabled.
 | 
			
		||||
 | 
			
		||||
to perform administrative tasks as is done with Linux privileged containers.
 | 
			
		||||
 | 
			
		||||
## Static Pods
 | 
			
		||||
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue