By default, the bundle come with a "auto" tag, which will activate privileged containers just when GPUs are detected.
You can enforce "false" to remove that, but then you won't be able to run GPU workloads.
Or you can enforce "yes" and have them activated all the time.
Does that answer the question? Not sure if I understood it right.
Just because I want to use a GPU shouldn't require the power to change the clock, switch UIDs, chown files, mess with logs, reboot the machine, etc.
That said, if you set the allow-privileged flag to false GPU drivers will still be installed but you may not be able to make use of the cuda cores
https://kubernetes.io/docs/concepts/storage/volumes/#hostpat...
I suspect that there is a bug somewhere.
https://github.com/madeden/blogposts/blob/master/k8s-gpu-clo...
You don't need to mount the /dev entries into the container at all. The experimental support creates them automatically for you when you are using GPU resources. Perhaps it's device nodes, not the libraries that required privileges?
OK I gave it a try and you are absolutely right. For the nvidia-smi, I could run it the /dev/nvidia0, which is cool.
I was also able to run it unprivileged. I guess my mistake was to believe the example from the docs and not test without.
Thanks for sharing that, I'll update my charts and the post accordingly.