mirror of
https://github.com/k3s-io/kubernetes.git
synced 2025-07-27 13:37:30 +00:00
Use read-only root filesystem capabilities of appc & rkt
This commit is contained in:
parent
d6d0a6eb83
commit
239c04d60d
@ -767,6 +767,7 @@ func (r *Runtime) newAppcRuntimeApp(pod *api.Pod, c api.Container, pullSecrets [
|
|||||||
Name: convertToACName(c.Name),
|
Name: convertToACName(c.Name),
|
||||||
Image: appcschema.RuntimeImage{ID: *hash},
|
Image: appcschema.RuntimeImage{ID: *hash},
|
||||||
App: imgManifest.App,
|
App: imgManifest.App,
|
||||||
|
ReadOnlyRootFS: *c.SecurityContext.ReadOnlyRootFilesystem,
|
||||||
Annotations: []appctypes.Annotation{
|
Annotations: []appctypes.Annotation{
|
||||||
{
|
{
|
||||||
Name: *appctypes.MustACIdentifier(k8sRktContainerHashAnno),
|
Name: *appctypes.MustACIdentifier(k8sRktContainerHashAnno),
|
||||||
|
Loading…
Reference in New Issue
Block a user