coredns can't start when using crio and with selinux on
问题 I know this question is asked many times, but all about docker, this time is crio. CentOS Linux release 7.6 CRI-O Version: 1.16.1 Kubernetes: v1.16.3 KubeAdm: v1.16.3 CoreDNS pods are in Error/CrashLoopBackOff state, and audit.log shows selinux prevents CoreDNS to read from /var/lib/kubelet/container_id/volumes/ type=AVC msg=audit(1576203392.727:1431): avc: denied { read } for pid=15866 comm="coredns" name="Corefile" dev="dm-0" ino=35369330 scontext=system_u:system_r:container_t:s0:c307,c586