# How can we make sure at the node level that pods do not run as root user

**URL:** <https://discuss.kubernetes.io/t/how-can-we-make-sure-at-the-node-level-that-pods-do-not-run-as-root-user/29147>\
**Category:** General Discussions\
**Created:** [July 25, 2024, 4:37pm UTC](https://discuss.kubernetes.io/t/how-can-we-make-sure-at-the-node-level-that-pods-do-not-run-as-root-user/29147 "2024-07-25T16:37:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![GodsGiftedChild](https://avatars.discourse-cdn.com/v4/letter/g/a88e57/32.png) [@GodsGiftedChild](https://discuss.kubernetes.io/u/GodsGiftedChild)\
**Post date:** [July 25, 2024, 4:37pm UTC](https://discuss.kubernetes.io/t/how-can-we-make-sure-at-the-node-level-that-pods-do-not-run-as-root-user/29147/1 "2024-07-25T16:37:15Z")

</div>

Hello Guys,

This is an interview question. The interviewer asked what can we do to make sure at the node level that pods do not run as root user ?

My answer was, if we run the kubernetes server and client components as a non-root user then the container it spaws will also run as a non-root user.

Is that right ? Can we run the kubernetes server and client components as a non-root user and would it spawn a non-root container if we did ?

---

<div class="post-metadata">

**Author:** ![Iggy](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/iggy/32/15445_2.png) [@Iggy](https://discuss.kubernetes.io/u/Iggy)\
**Post date:** [July 26, 2024, 6:30am UTC](https://discuss.kubernetes.io/t/how-can-we-make-sure-at-the-node-level-that-pods-do-not-run-as-root-user/29147/2 "2024-07-26T06:30:15Z")

</div>

👋 hello @GodsGiftedChild,

From my knowledge, this is not a true state.

There are two approaches to how you can control the level of access for the container namespace isolation towards host system calls.

1. [podSecurityContext](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.30/#podsecuritycontext-v1-core) → holds pod-level security attributes and common container settings.
  - more about this one use `kubectl explain deployment.spec.template.spec.securityContext` on you’re cluster side

2. [securityContext](https://kubernetes.io/docs/reference/generated/kubernetes-api/v1.30/#securitycontext-v1-core) → holds a security configuration that will be applied to a container.
  - more about this one use `kubectl explain deployment.spec.template.spec.containers.securityContext` on you’re cluster side

> NOTE: When both are set, the values in SecurityContext take precedence.

This is in high-level view, but if want to go deep into it then you can check this documentation → [security-context](https://kubernetes.io/docs/tasks/configure-pod-container/security-context/)
