mirror of
https://github.com/kata-containers/kata-containers.git
synced 2025-07-13 23:24:14 +00:00
Merge pull request #408 from amshinde/remove-privileged-limitation
Limitations: Remove privileged flag limitation
This commit is contained in:
commit
6301fbe458
@ -220,10 +220,12 @@ See more documentation at
|
|||||||
|
|
||||||
### docker run --privileged
|
### docker run --privileged
|
||||||
|
|
||||||
The `docker run --privileged` command is not supported in the runtime.
|
Privileged support in Kata is essentially different from `runc` containers.
|
||||||
There is no simple way to grant the VM access to all of the host devices that this command needs to be complete.
|
Kata does support `docker run --privileged` command, but in this case full access
|
||||||
|
to the guest VM is provided instead of the host.
|
||||||
The `--privileged` option can be used with `runc` containers and inter-mixed with running Kata Containers. This enables use of `--privileged` when necessary.
|
The container runs with elevated capabilities within the guest and is granted
|
||||||
|
access to guest devices instead of the host devices.
|
||||||
|
This is also true with using `securityContext privileged=true` with Kubernetes.
|
||||||
|
|
||||||
# Miscellaneous
|
# Miscellaneous
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user