DataKit Security¶
Some DataKit collectors need to read host files, access host networks, or load eBPF programs. Required permissions depend on the enabled collectors and deployment mode. This document explains common permissions for Kubernetes node deployments and how to adjust them.
Privilege Details¶
Pod-Level Privileges¶
| Setting | Purpose and impact |
|---|---|
hostPID: true |
Uses the host process namespace so the container can see host processes. Disabling it affects collectors that depend on this process view. |
hostNetwork: true |
Uses the host network namespace, allowing DataKit to access host interfaces and listen on node addresses. When disabling it, check data senders' destination addresses against the new network configuration. |
Container-Level Privileges¶
| Setting | Purpose and impact |
|---|---|
securityContext.privileged: true |
Grants broad kernel and device access. Standard node deployment templates enable it for collection features such as eBPF that need these permissions. |
| Running as root | Provides access to protected files and directories. Before switching to a non-root user, check access to collection and runtime directories. |
ports.hostPort |
Maps a container port to a node port for incoming data. A Kubernetes Service can provide a data endpoint after this mapping is removed. |
securityContext.readOnlyRootFilesystem: false |
Allows writes to the container root filesystem. Before setting it to true, provide writable volumes for runtime paths such as caches and logs. |
Permissions and host directory mounts together determine which resources a container can access. Existing hostPath mounts require a separate check when disabling a permission. See Kubernetes security contexts for field definitions.
Adjust Configuration¶
- Identify the collectors to retain and the host directories, networks, and devices they access before changing permissions. Disabling one collector does not remove another collector's need for the same permission.
- When switching data reception to a Kubernetes Service, update application destination addresses and ports, and check connectivity.
- Use
nodeSelectoror node affinity to select deployment nodes. Configuretolerationsas needed for tainted nodes. - After making changes, check collector startup logs and reported data to confirm that the required collection features still work.
GKE Autopilot uses dedicated deployment settings. See the GCP GKE Autopilot deployment guide.