Safety & Security · Data artifact

Container Security Context

Data artifactSafety & SecuritySafety, Security & Governancearc:ContainerSecurityContext

A per-workload security specification restricting the system resources and kernel capabilities a container may use.

Responsibility. Enforces least privilege on agent containers.

Also known as: Pod security context, Read-only root filesystem configuration, Container resource limits

constrainsconstrainsAgent Controller: constrainsAgent ControllerExecution Sandbox: constrainsExecution Sandbox
Direct neighbourhood (hover for relationship types)

Relationships

constrains control

Design guidance

Classification

Patterns
Least privilegeRead-only root filesystem with writable /tmp volumesHard CPU/memory limits
Technologies
Kubernetes securityContext
Quality attributes
Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)
Risks mitigated
Privilege escalation from a compromised agent container

Sources

  1. Ch4.3: T. Nguyen, "Container Orchestration and Edge Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.3. ISBN: 9798244538229.
  2. Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.