fsGroup — Setting Volume Group Ownership
Given the following partial pod spec: ```yaml securityContext: runAsUser: 1000 runAsGroup: 3000 fsGroup: 2000 ``` Which combination correctly describes the resulting permissions on a mounted volume?
Quick Answer
The correct answer is that the volume is owned by group 2000, while the container runs with user 1000 and group 3000. This is because `fsGroup: 2000` specifically sets the group ownership of any mounted volume to group ID 2000 and adds that group as a supplemental group for the container’s processes, while `runAsUser: 1000` and `runAsGroup: 3000` define the primary user and group for the running process. On the CKAD exam, this concept tests your understanding of how security contexts interact with volume permissions—a common trap is confusing `runAsGroup` with `fsGroup`, thinking the volume inherits the container’s primary group. In reality, `fsGroup` overrides volume group ownership independently. A helpful memory tip: think of `fsGroup` as “filesystem group”—it only touches the volume’s group, not the process’s primary group.
⚠ Common exam trap
It's easy for candidates to confuse `runAsGroup` (which sets the container's primary GID) with `fsGroup` (which sets the volume's group ownership and adds a supplemental group), leading candidates to incorrectly assign the volume's group to the container's primary group or vice versa.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Volume owned by user 1000, group 2000; container runs with user 1000 and group 3000
With `runAsUser: 1000`, the container's primary user ID is set to 1000, and this also makes the volume owned by user 1000. `runAsGroup: 3000` sets the container's primary group ID to 3000. `fsGroup: 2000` changes the group ownership of the mounted volume to group 2000 and adds it as a supplemental group. Thus, the volume is owned by user 1000 and group 2000, and the container runs with UID 1000 and GID 3000.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Volume owned by user 2000, group 1000; container runs with user 2000 and group 1000
Why it's wrong here
runAsUser sets the container process UID to 1000 and runAsGroup its primary GID to 3000; fsGroup 2000 changes the mounted volume's group ownership. This option swaps those values, confusing fsGroup with runAsUser. fsGroup would be the correct mechanism when only volume group ownership needs setting.
- ✗
Volume owned by user 3000, group 2000; container runs with user 1000 and group 3000
Why it's wrong here
fsGroup 2000 sets the volume's group ownership, not 3000, and the container's primary group comes from runAsGroup 3000, not the volume owner. It is tempting because it correctly pairs runAsUser 1000 with runAsGroup 3000 for the process, but misassigns fsGroup's effect on the volume.
- ✓
Volume owned by user 1000, group 2000; container runs with user 1000 and group 3000
Why this is correct
fsGroup 2000 sets the mounted volume's group ownership and permissions, so the volume is owned by group 2000, while runAsGroup 3000 governs the container process's primary group. The volume's user ownership comes from runAsUser 1000. These are distinct axes, which is why the volume group and process group differ.
- ✗
Volume owned by user 1000, group 3000; container runs with user 1000 and group 2000
Why it's wrong here
fsGroup 2000 makes the volume group-owned by 2000, and runAsGroup 3000 sets the container's primary GID, so both halves are inverted. It is tempting because it correctly keeps runAsUser 1000 for the process, yet confuses which directive governs volume group ownership.
Go deeper
Related to this question
About these practice questions
One of 826 original CKAD practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CKAD
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A Pod spec includes 'securityContext' with 'runAsUser: 1000' and 'runAsGroup: 3000'. The container process inside the pod is expected to write to a mounted volume. Which securityContext field should be set to ensure the volume's group ownership is 3000?
medium- A.supplementalGroups: [3000]
- B.fsGroup: 1000
- ✓ C.fsGroup: 3000
- D.runAsGroup: 3000
Why C: The `fsGroup` field in the Pod's `securityContext` specifies the group ID (GID) that Kubernetes should assign to any volume mounted into the Pod. When `fsGroup: 3000` is set, Kubernetes recursively changes the ownership of the volume's files and directories to group ID 3000, and any new files created by the container process will inherit that group ownership. This ensures the container process, which runs with `runAsGroup: 3000`, can write to the volume without permission errors.
Variation 2. A pod is running with a SecurityContext that sets 'runAsUser: 1000' and 'runAsGroup: 3000'. The container process is running as user 1000. However, the container needs to access a file on a mounted volume that is owned by user 1000 and group 2000. Which SecurityContext setting should be added to ensure the container can read the file?
medium- ✓ A.Set fsGroup: 2000 in the pod-level securityContext
- B.Set readOnlyRootFilesystem: true
- C.Set runAsGroup: 2000
- D.Add capability: CAP_DAC_READ_SEARCH
Why A: fsGroup is a pod-level SecurityContext setting that causes Kubernetes to recursively change the group ownership of the volume's files to the specified GID and adds the container's supplemental group list. Setting fsGroup: 2000 makes the mounted volume files group-owned by GID 2000, and the container process running as user 1000 inherits 2000 as a supplemental group, granting read access. This is the canonical fix when a volume's group ownership does not match the container's primary runAsGroup.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKAD practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKAD exam.