From de242faccadd0d8c6caa9bd0270dbc1920d02e3a Mon Sep 17 00:00:00 2001 From: Ian Campbell Date: Fri, 15 Dec 2017 10:16:37 +0000 Subject: [PATCH] auditd: move config into build.yml Signed-off-by: Ian Campbell --- pkg/auditd/Dockerfile | 2 -- pkg/auditd/build.yml | 9 +++++++++ 2 files changed, 9 insertions(+), 2 deletions(-) diff --git a/pkg/auditd/Dockerfile b/pkg/auditd/Dockerfile index 5c6027d98..7bdb35c68 100644 --- a/pkg/auditd/Dockerfile +++ b/pkg/auditd/Dockerfile @@ -25,5 +25,3 @@ COPY audit.rules /etc/audit COPY runaudit.sh /usr/bin CMD ["/sbin/tini", "/usr/bin/runaudit.sh"] - -LABEL org.mobyproject.config='{"pid": "host", "binds": ["/var/log:/var/log"], "capabilities": ["CAP_AUDIT_CONTROL", "CAP_AUDIT_READ", "CAP_AUDIT_WRITE", "CAP_SYS_NICE"]}' diff --git a/pkg/auditd/build.yml b/pkg/auditd/build.yml index 82454acfd..3388e2f64 100644 --- a/pkg/auditd/build.yml +++ b/pkg/auditd/build.yml @@ -1,2 +1,11 @@ image: auditd network: true +config: + pid: host + binds: + - /var/log:/var/log + capabilities: + - CAP_AUDIT_CONTROL + - CAP_AUDIT_READ + - CAP_AUDIT_WRITE + - CAP_SYS_NICE