Reference meta
unsafe
Declare a narrowly scoped, audited exception to Kix package safety rules.
meta.unsafe is a list of named exceptions to structural and security rules:
meta = { version = "1.0.0"; unsafe = [ "run-as-root" ];};The vocabulary is closed. An unknown name is an evaluation error, including when the package does not render a resource that would use the exception.
| Grant | Effect |
|---|---|
raw-pvc | Allows the package to build a PersistentVolumeClaim directly. Without it, packages must receive storage through a dependency. |
host-network | Exempts the package from security.noHostNetwork, which checks hostNetwork, hostPID, and hostIPC. |
privileged | Exempts the package from security.noPrivileged. |
run-as-root | Exempts the package from security.nonRoot. |
cluster-admin | Exempts the package from security.noClusterAdmin, which refuses a ClusterRoleBinding to cluster-admin and a ClusterRole that grants every verb on every resource in every API group. Velero holds it: a backup tool reads every kind and recreates any kind on restore. |
Every declared grant produces an info-level
architecture.unsafeGrants scorecard finding. This keeps the exception
visible even though the waived rule does not report a finding.
Grants do not change the target cluster’s capabilities or Kubernetes
admission policy. For example, privileged suppresses the scorecard rule, but
a workload still fails evaluation when
cluster.capabilities.privilegedContainers = false, and the API server may
still reject it under Pod Security Admission.
Keep the list on the package, not on an individual cluster instance, and add a source comment explaining why the workload cannot satisfy the normal rule. The grant then travels with every use of the package and remains visible in the scorecard.