Run privileged open source workloads on GKE Autopilot Stay organized with collections Save and categorize content based on your preferences.
About allowlists for privileged Autopilot workloads
By default, GKE Autopilot enforces security constraintsthat reject workloads that need elevated privileges in the cluster. For example,you can't, by default, run a Pod that enables privileged mode or adds theNET_RAW Linux capability.
You can optionally run a specific set of privileged workloads fromAutopilot partnersand from certain open source projects in Autopilot mode.
To deploy privileged open source workloads in Autopilot mode, youdo the following:
- Install anallowlist for the workload by deploying an
AllowlistSynchronizerobject. The AllowlistSynchronizer installs theallowlist as aWorkloadAllowlistobject and manages its lifecycle.For instructions, seeRun privileged workloads from GKE Autopilot partners. - Deploy the privileged open source workload in your cluster by followingthe installation steps in the project's documentation.
Privileged open source workloads with Autopilot support
The following table describes the privileged open source workloads that you canrun on Autopilot. To enable a workload,create anAllowlistSynchronizer resource with the path to the allowlists for thatworkload in theallowlistPaths field.
| Privileged open source workloads for Autopilot | Allowlist path |
|---|---|
Grafana/alloy/* | |
Grafana/beyla/* |
This table describes only the open-source workloads that need elevatedprivileges and are supported on Autopilot. Open-source software thatrequires elevated privileges and is not listed in this table might not work onAutopilot. If an open source application doesn't violate the defaultsecurity constraints in Autopilot, you can run the applicationwithout an allowlist.
What's next
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-02-18 UTC.