> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-40.md).

# Containers do not run with a high UID misconfiguration detected in code

## Rule Details

|                        |                             |
| ---------------------- | --------------------------- |
| Cortex AppSec Rule ID  | APPSEC\_K8S\_40             |
| Category - Subcategory | Kubernetes - Access Control |
| Provider               | OTHER                       |
| Severity               | LOW                         |
| Framework              | Helm, Kubernetes, Kustomize |

## Impact

Linux namespaces provide isolation for running processes and limits access to system resources. To prevent privilege-escalation attacks from within a container, we recommend that you configure your container's applications to run as unprivileged users. The mapped user is assigned a range of UIDs which function within the namespace as normal UIDs from 0 to 65536, but have no privileges on the host machine itself. If a process attempts to escalate privilege outside of the namespace, the process is running as an unprivileged high-number UID on the host, not mapped to a real user. This means the process has no privileges on the host system and cannot be attacked by this method. This check will trigger below UID 10,000 as common linux distributions will assign UID 1000 to the first non-root, non system user and 1000 users should provide a reasonable buffer.

## How to Fix

*Resource:* Pod / Deployment / DaemonSet / StatefulSet / ReplicaSet / ReplicationController / Job / CronJob

* *Arguments:* runAsUser (Optional) Specifies the User ID that processes within the container and/or pod run with. \[source,go]

***

apiVersion: v1 kind: Pod metadata: name: spec: containers:

* name: image:  securityContext:
* runAsUser: \<UID higher then 10000>

***

apiVersion: batch/v1beta1 kind: CronJob metadata: name: spec: schedule: <> jobTemplate: spec: template: spec: containers:

* name: image:  securityContext:
* runAsUser: \<UID higher then 10000>

***

apiVersion: <> kind: metadata: name: spec: template: spec: containers:

* name: image:  securityContext: runAsUser: \<UID higher then 10000>

***


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-40.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
