VectleSkillskustomize build fails: security; file '[file]' is not in or below '[dir]'

kustomize build fails: security; file '[file]' is not in or below '[dir]'

Export

Routes kustomize load-restriction errors. Use when kustomize build refuses a file outside the kustomization root (load-restrictor / security error). Not for duplicate-resource or patch errors.

Kustomize refuses to read files outside the kustomization root by default - a deliberate sandbox so builds can not reach across the filesystem. Restructure so everything the build needs lives under the root (move the shared file in, or invert the layout so the kustomization sits above both), or pass --load-restrictor LoadRestrictionsNone when you accept the risk. Prefer restructuring; the flag disables the guard for the whole build.

The error

Error: security; file '[file]' is not in or below '[dir]'

What to do

  1. Find the offending reference:
grep -rn '[file]' kustomization.yaml

Expected: Shows the resource/patch path escaping the root.

  1. Move the file under the kustomization root and update the relative path.

Expected: Reference stays inside the tree.

  1. Rebuild:
kustomize build [dir]

Expected: Build succeeds.

  1. Last resort only:
kustomize build --load-restrictor LoadRestrictionsNone [dir]

Expected: Build succeeds with the sandbox off.

When this applies

  • the exact security; file ... is not in or below message
  • shared files referenced via ../..
  • monorepo layouts where the kustomization sits deep

When it does NOT apply

  • remote bases failing (network/auth, not the sandbox)
  • file not found errors (the path is wrong, not restricted)

Works with

kustomize 4.x/5.x; kubectl built-in kustomize

accumulating resources ...: security; ... is not in or below

Same guard, hit while walking resources. Same restructure-or-flag fix.

Why it happens

Kustomize treats the kustomization.yaml directory as the build root and rejects reads above it, so a build can not silently depend on files outside what you versioned together.

Edge cases

  • Components and remote bases have their own roots - the restriction applies per kustomization.
  • kubectl apply -k accepts --load-restrictor too, for the same escape hatch.

Resolved from

gh:mlopsmenacommunity/website (kustomize guide) - https://github.com/mlopsmenacommunity/website/blob/HEAD/content/student-guides/kustomize/mid-detailed.md

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=kustomize+build+fails%3A+security%3B+file+%27%5Bfile%5D%27+is+not+in+or+below+%27%5Bdir%5D%27&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.