Skip to content
kix /docs
Install the CLI

Reference meta

unsafe

Declare a narrowly scoped, audited exception to Kix package safety rules.

meta.unsafe is a list of named exceptions to structural and security rules:

meta = {
version = "1.0.0";
unsafe = [ "run-as-root" ];
};

The vocabulary is closed. An unknown name is an evaluation error, including when the package does not render a resource that would use the exception.

GrantEffect
raw-pvcAllows the package to build a PersistentVolumeClaim directly. Without it, packages must receive storage through a dependency.
host-networkExempts the package from security.noHostNetwork, which checks hostNetwork, hostPID, and hostIPC.
privilegedExempts the package from security.noPrivileged.
run-as-rootExempts the package from security.nonRoot.
cluster-adminExempts the package from security.noClusterAdmin, which refuses a ClusterRoleBinding to cluster-admin and a ClusterRole that grants every verb on every resource in every API group. Velero holds it: a backup tool reads every kind and recreates any kind on restore.

Every declared grant produces an info-level architecture.unsafeGrants scorecard finding. This keeps the exception visible even though the waived rule does not report a finding.

Grants do not change the target cluster’s capabilities or Kubernetes admission policy. For example, privileged suppresses the scorecard rule, but a workload still fails evaluation when cluster.capabilities.privilegedContainers = false, and the API server may still reject it under Pod Security Admission.

Keep the list on the package, not on an individual cluster instance, and add a source comment explaining why the workload cannot satisfy the normal rule. The grant then travels with every use of the package and remains visible in the scorecard.