auditd: move config into build.yml

Signed-off-by: Ian Campbell <ijc@docker.com>
This commit is contained in:
Ian Campbell 2017-12-15 10:16:37 +00:00
parent c2a4b6d08e
commit de242facca
2 changed files with 9 additions and 2 deletions

View File

@ -25,5 +25,3 @@ COPY audit.rules /etc/audit
COPY runaudit.sh /usr/bin
CMD ["/sbin/tini", "/usr/bin/runaudit.sh"]
LABEL org.mobyproject.config='{"pid": "host", "binds": ["/var/log:/var/log"], "capabilities": ["CAP_AUDIT_CONTROL", "CAP_AUDIT_READ", "CAP_AUDIT_WRITE", "CAP_SYS_NICE"]}'

View File

@ -1,2 +1,11 @@
image: auditd
network: true
config:
pid: host
binds:
- /var/log:/var/log
capabilities:
- CAP_AUDIT_CONTROL
- CAP_AUDIT_READ
- CAP_AUDIT_WRITE
- CAP_SYS_NICE