-
Notifications
You must be signed in to change notification settings - Fork 18.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
use lxc.auto.mount to ensure proc and sys are readonly #10205
use lxc.auto.mount to ensure proc and sys are readonly #10205
Conversation
Set lxc.auto.mount = proc:mixed in unprivilged mode. This ensures that lxc mounts sys and proc/sysrq-trigger as readonly. Signed-off-by: Abin Shahab <ashahab@altiscale.com> (github: ashahab-altiscale) Docker-DCO-1.1-Signed-off-by: Abin Shahab <ashahab@altiscale.com> (github: ashahab-altiscale)
this needs documenation - and please, include any contrasts bewteen the lxc driver and the libcontainer one. |
I'm running this on jenkins here https://jenkins.dockerproject.com/job/LXC%20PR%20Test/label=ubuntu-aufs-lxc/4/console |
@ashahab-altiscale you will have to rebase now that your other PR is merged |
69c7526
to
d821c63
Compare
@SvenDowideit @dineshs-altiscale @crosbymichael rebased and documented. |
it's building here https://jenkins.dockerproject.com/job/LXC%20PR%20Test/label=ubuntu-aufs-lxc/4/console :) |
LGTM |
LGTM @ashahab-altiscale is having a productive week! : ) |
👍 ping @crosbymichael |
LGTM |
…proc-sys use lxc.auto.mount to ensure proc and sys are readonly
Set lxc.auto.mount = proc:mixed in unprivilged mode. This ensures that lxc mounts sys and proc/sysrq-trigger as readonly.
Merge after #10190