diff --git a/docker/driver-loader/Dockerfile b/docker/driver-loader/Dockerfile index ec39c8f8..4ea9dacb 100644 --- a/docker/driver-loader/Dockerfile +++ b/docker/driver-loader/Dockerfile @@ -3,7 +3,7 @@ FROM falcosecurity/falco:${FALCO_IMAGE_TAG} LABEL maintainer="cncf-falco-dev@lists.cncf.io" -LABEL usage="docker run -i -t -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro --name NAME IMAGE" +LABEL usage="docker run -i -t --privileged -v /root/.falco:/root/.falco -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro -v /etc:/host/etc:ro --name NAME IMAGE" ENV HOST_ROOT /host ENV HOME /root diff --git a/docker/falco/Dockerfile b/docker/falco/Dockerfile index 380c1877..00463247 100644 --- a/docker/falco/Dockerfile +++ b/docker/falco/Dockerfile @@ -2,7 +2,7 @@ FROM debian:stable LABEL maintainer="cncf-falco-dev@lists.cncf.io" -LABEL usage="docker run -i -t -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro --name NAME IMAGE" +LABEL usage="docker run -i -t --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro -v /boot:/host/boot:ro -v /lib/modules:/host/lib/modules:ro -v /usr:/host/usr:ro -v /etc:/host/etc --name NAME IMAGE" ARG FALCO_VERSION=latest ARG VERSION_BUCKET=deb diff --git a/docker/no-driver/Dockerfile b/docker/no-driver/Dockerfile index d316815e..9dddb4f5 100644 --- a/docker/no-driver/Dockerfile +++ b/docker/no-driver/Dockerfile @@ -1,7 +1,5 @@ FROM ubuntu:18.04 as ubuntu -LABEL maintainer="cncf-falco-dev@lists.cncf.io" - ARG FALCO_VERSION ARG VERSION_BUCKET=bin @@ -22,6 +20,11 @@ RUN sed -e 's/time_format_iso_8601: false/time_format_iso_8601: true/' < /falco/ FROM scratch +LABEL maintainer="cncf-falco-dev@lists.cncf.io" + +LABEL usage="docker run -i -t --privileged -v /var/run/docker.sock:/host/var/run/docker.sock -v /dev:/host/dev -v /proc:/host/proc:ro --name NAME IMAGE" +# NOTE: for the "least privileged" use case, please refer to the official documentation + ENV HOST_ROOT /host ENV HOME /root