# securityContext runAsNonRoot not working

**URL:** <https://discuss.kubernetes.io/t/securitycontext-runasnonroot-not-working/12340>\
**Category:** General Discussions\
**Created:** [August 12, 2020, 5:13pm UTC](https://discuss.kubernetes.io/t/securitycontext-runasnonroot-not-working/12340 "2020-08-12T17:13:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdelghani](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@Abdelghani](https://discuss.kubernetes.io/u/Abdelghani)\
**Post date:** [August 12, 2020, 5:13pm UTC](https://discuss.kubernetes.io/t/securitycontext-runasnonroot-not-working/12340/1 "2020-08-12T17:13:50Z")

</div>

Hi,  
I am testing with securityContext but I cant start a pod when I set runAsNonRoot to true.  
I use vagrant to deploy a master and two minions and ssh to the host machine as the user abdelghani :

> id $USER  
> uid=1001(abdelghani) gid=1001(abdelghani) groups=1001(abdelghani),27(sudo)

### Cluster information:

Kubernetes version: 4.4.0-185-generic  
Cloud being used: (put bare-metal if not on a public cloud)  
Installation method: manual  
Host OS: ubuntu16.04.6  
CNI and version:  
CRI and version:

```
apiVersion: v1
kind: Pod
metadata:
  name: buggypod
spec:
  containers:
  - name: container
    image: nginx
    securityContext:        
      runAsNonRoot: true

```

I do :  
`kubectl apply -f pod.yml`  
it says `pod mybugypod created` but when I check with :  
`kubectl get pods`  
the pod’s status is `CreateContainerConfigError`

what is it I am doing wrong?

---

<div class="post-metadata">

**Author:** ![tej-singh-rana](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/tej-singh-rana/32/5921_2.png) [@tej-singh-rana](https://discuss.kubernetes.io/u/tej-singh-rana)\
**Post date:** [August 14, 2020, 10:55am UTC](https://discuss.kubernetes.io/t/securitycontext-runasnonroot-not-working/12340/2 "2020-08-14T10:55:37Z")

</div>

Hello, Abdelghani  
If you want to run with your username then create dockerfile define user in the instructions. Build the image and deploy in the k8s. Nginx required root privilege so normal user cannot start. Maybe the reason.

---

<div class="post-metadata">

**Author:** ![Abdelghani](https://avatars.discourse-cdn.com/v4/letter/a/49beb7/32.png) [@Abdelghani](https://discuss.kubernetes.io/u/Abdelghani)\
**Post date:** [August 16, 2020, 4:07pm UTC](https://discuss.kubernetes.io/t/securitycontext-runasnonroot-not-working/12340/3 "2020-08-16T16:07:15Z")

</div>

Thx for your answer. Issue solved.
