<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Security on Hex Blog</title><link>https://hex-go.github.io/tags/security/</link><description>Recent content in Security on Hex Blog</description><generator>Hugo -- gohugo.io</generator><language>zh</language><managingEditor>hex-py@gmail.com (Hex)</managingEditor><webMaster>hex-py@gmail.com (Hex)</webMaster><copyright>©2026, All Rights Reserved</copyright><lastBuildDate>Sun, 28 Jun 2020 09:36:19 +0000</lastBuildDate><atom:link href="https://hex-go.github.io/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Kubernetes 集群中以非 root 启动容器</title><link>https://hex-go.github.io/posts/kubernetes/2020-06-28-docker-kubernetes%E9%9B%86%E7%BE%A4%E4%B8%AD%E4%BB%A5%E9%9D%9Eroot%E5%90%AF%E5%8A%A8%E5%AE%B9%E5%99%A8/</link><pubDate>Sun, 28 Jun 2020 09:36:19 +0000</pubDate><author>hex-py@gmail.com (Hex)</author><atom:modified>Sun, 28 Jun 2020 09:36:19 +0000</atom:modified><guid>https://hex-go.github.io/posts/kubernetes/2020-06-28-docker-kubernetes%E9%9B%86%E7%BE%A4%E4%B8%AD%E4%BB%A5%E9%9D%9Eroot%E5%90%AF%E5%8A%A8%E5%AE%B9%E5%99%A8/</guid><description>重要 容器默认以 root 运行，与宿主机 root 共享同一 UID 空间。一旦容器可访问宿主机资源，等同于宿主机 root 权限。 1. 问题 安全漏洞 CVE-2019-11245：容</description><dc:creator>Hex</dc:creator><category>Kubernetes</category><category>Security</category><category>Kubernetes</category></item></channel></rss>