Safety & Security · Data artifact
Container Security Context
Data artifactSafety & SecuritySafety, Security & Governancearc:ContainerSecurityContext
A per-workload security specification restricting the system resources and kernel capabilities a container may use.
Responsibility. Enforces least privilege on agent containers.
Also known as: Pod security context, Read-only root filesystem configuration, Container resource limits
Relationships
constrains control
- Agent Controller abstract Ch4.3
- Execution Sandbox abstract Ch9.3
Design guidance
- SHOULD mount the container root filesystem read-only, granting write access only to required temporary paths.
Classification
- Patterns
- Least privilegeRead-only root filesystem with writable /tmp volumesHard CPU/memory limits
- Technologies
- Kubernetes securityContext
- Quality attributes
- Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)
- Risks mitigated
- Privilege escalation from a compromised agent container
Sources
- Ch4.3: T. Nguyen, "Container Orchestration and Edge Deployment," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.3. ISBN: 9798244538229.
- Ch9.3: T. Nguyen, "Sandboxing and Transparency Foundations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.3. ISBN: 9798244538229.