Skip to content

Commit

Permalink
Update the use of privileged flag in aws-vpc-cni manifest (#2555)
Browse files Browse the repository at this point in the history
  • Loading branch information
jaydeokar authored Sep 11, 2023
1 parent 56390a1 commit 2835a36
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ For a detailed explanation, see [`WARM_ENI_TARGET`, `WARM_IP_TARGET` and `MINIMU

## Privileged mode

VPC CNI makes use of privileged mode (`privileged: true`) in the manifest only for its init container. This elevated privilege is required to set the networking kernel parameters.
VPC CNI makes use of privileged mode (`privileged: true`) in the manifest for its `aws-vpc-cni-init` and `aws-eks-nodeagent` containers. `aws-vpc-cni-init` container requires elevated privilege to set the networking kernel parameters while `aws-eks-nodeagent` container requires these privileges for attaching BPF probes to enforce network policy

## Network Policies

Expand Down

0 comments on commit 2835a36

Please sign in to comment.