kustomize build fails: security; file '[file]' is not in or below '[dir]'
Routes kustomize load-restriction errors. Use when kustomize build refuses a file outside the kustomization root (load-restrictor / security error). Not for duplicate-resource or patch errors.
Kustomize refuses to read files outside the kustomization root by default - a deliberate sandbox so builds can not reach across the filesystem. Restructure so everything the build needs lives under the root (move the shared file in, or invert the layout so the kustomization sits above both), or pass --load-restrictor LoadRestrictionsNone when you accept the risk. Prefer restructuring; the flag disables the guard for the whole build.
The error
Error: security; file '[file]' is not in or below '[dir]'What to do
- Find the offending reference:
grep -rn '[file]' kustomization.yamlExpected: Shows the resource/patch path escaping the root.
Move the file under the kustomization root and update the relative path. Expected: Reference stays inside the tree.
- Rebuild:
kustomize build [dir]Expected: Build succeeds.
- Last resort only:
kustomize build --load-restrictor LoadRestrictionsNone [dir]Expected: Build succeeds with the sandbox off.
When this applies
- the exact security; file ... is not in or below message
- shared files referenced via ../..
- monorepo layouts where the kustomization sits deep
When it does NOT apply
- remote bases failing (network/auth, not the sandbox)
- file not found errors (the path is wrong, not restricted)
Works with
kustomize 4.x/5.x; kubectl built-in kustomize
accumulating resources ...: security; ... is not in or below
Same guard, hit while walking resources. Same restructure-or-flag fix.
Why it happens
Kustomize treats the kustomization.yaml directory as the build root and rejects reads above it, so a build can not silently depend on files outside what you versioned together.
Edge cases
- Components and remote bases have their own roots - the restriction applies per kustomization.
- kubectl apply -k accepts --load-restrictor too, for the same escape hatch.
Resolved from
gh:mlopsmenacommunity/website (kustomize guide) - https://github.com/mlopsmenacommunity/website/blob/HEAD/content/student-guides/kustomize/mid-detailed.md