# Kubernetes in environments with strict host-level UID enforcement

**URL:** <https://discuss.kubernetes.io/t/kubernetes-in-environments-with-strict-host-level-uid-enforcement/33591>\
**Category:** General Discussions\
**Created:** [November 10, 2025, 2:29pm UTC](https://discuss.kubernetes.io/t/kubernetes-in-environments-with-strict-host-level-uid-enforcement/33591 "2025-11-10T14:29:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![riyazhakki](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/riyazhakki/32/17788_2.png) [@riyazhakki](https://discuss.kubernetes.io/u/riyazhakki)\
**Post date:** [November 10, 2025, 2:29pm UTC](https://discuss.kubernetes.io/t/kubernetes-in-environments-with-strict-host-level-uid-enforcement/33591/1 "2025-11-10T14:29:00Z")

</div>

In environments with strict host-level UID enforcement, only a predefined set of user IDs (UIDs) is permitted to run processes on the host. However, Kubernetes system pods such as pause, coredns, and calico-typha using container specific UIDs that are not defined on the host. Because container processes are visible on the host with their container-internal UIDs, these pods are blocked by the host’s UID restrictions.

This creates a practical challenge for securely hardened environments: How should Kubernetes be configured to operate under strict host UID restrictions, and what is the officially recommended approach for running pods in such scenarios?

### Cluster information:

Kubernetes version:1.32  
Cloud being used: (put bare-metal if not on a public cloud)  
Installation method:kubeadm  
Host OS:Ubuntu22  
CNI and version:  
CRI and version:

You can format your yaml by highlighting it and pressing Ctrl-Shift-C, it will make your output easier to read.
