Permissions for the /dev/{kfd,dri/renderXXXX} devices in containers
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 395
- Forks
- 85
- Avg merge
- 2d 10h
- Merged PRs (30d)
- 16
Description
Hi folks!
I am trying the AMD device plugin on my system, deployed as Systemd unit on Debian 11 (so not a DaemonSet, but directly on the K8s node). Everything works fine and I am able to see two devices in my test container:
- /dev/kfd
- /dev/dri/renderD128
I am trying to run the container with an unpriviledged user, like nobody, but I am struggling to assign the proper permissions to the above devices. In the container I see something like the following (tested via nsenter):
root@alexnet-tf-gpu-pod:/# ls -l /dev/kfd
crw-rw---- 1 root 106 242, 0 Apr 18 15:58 /dev/kfd
root@alexnet-tf-gpu-pod:/# ls -l /dev/dri/renderD128
crw-rw---- 1 root 106 226, 128 Apr 18 15:58 /dev/dri/renderD128
The gid 106 is the render group on the underlying "bare metal" K8s worker OS, that gets mapped to the test container, but in this way I don't have a clear way to add nobody to render or similar (in the Docker image). Is there a best practice that you can suggest?
Thanks in advance!
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No source file or test is named. Start by reproducing the /dev/kfd and /dev/dri/renderD128 permissions for an unprivileged user in the Kubernetes test container, then inspect the AMD device plugin's device allocation and container setup. Done means identifying and documenting a supported way to grant the required device access without running as root.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go, kubernetes
- Domain
- infrastructure, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100