Commit Graph

1878 Commits

Author SHA1 Message Date
Justin Cormack
10e4eb84ec Merge pull request #851 from justincormack/push-image
Push a copy of the Moby base image to mobylinux/mobylinux
2016-12-07 13:58:49 -08:00
Justin Cormack
26ffe9f123 Merge pull request #849 from riyazdf/kexec-kernel-config
Disable kexec from kernel_config
2016-12-07 13:55:42 -08:00
Justin Cormack
2897b808bb Push a copy of the Moby base image to mobylinux/mobylinux
This will be used for ongoing security scanning.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-07 12:10:39 -08:00
Riyaz Faizullabhoy
2e8a6143dd Disable kexec from kernel_config, revert sysctl config because key is now unknown
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-07 11:43:10 -08:00
Justin Cormack
dbe24caa57 Merge pull request #840 from riyazdf/kexec-load
Disable kexec load in sysctl config
2016-12-07 10:44:44 -08:00
Justin Cormack
836954ab66 Merge pull request #848 from justincormack/sha-missing
Add some missing sha256 tags
2016-12-07 00:04:04 -08:00
Justin Cormack
b329aee664 Add some missing sha256 tags
These got missed in the previous commits.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-06 18:49:44 -08:00
Justin Cormack
2789f663b5 Merge pull request #846 from justincormack/trim-cond-mac
Only TRIM on Mac if configured via database
2016-12-06 08:58:07 -08:00
Justin Cormack
f2c2534608 Only TRIM on Mac if configured via database
Stops unnecessary log spam.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-06 08:50:45 -08:00
Justin Cormack
63401b8faa Merge pull request #845 from justincormack/15min
Typo in crontab
2016-12-06 08:41:52 -08:00
Justin Cormack
a5fa2fa133 Typo in crontab
Its 15min not 15m

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-06 08:37:04 -08:00
Justin Cormack
5a1925b6fe Merge pull request #844 from djs55/mac-trim
Use TRIM on Mac as well as Windows
2016-12-06 08:13:01 -08:00
David Scott
40e7dbbf8b Use TRIM on Mac as well as Windows
Previously we only ran `fstrim` on Windows. Docker for Mac now supports
TRIM so we should run `fstrim` there too.

Note it's possible to turn off TRIM on the Mac at the virtual hardware
level via the database, but this should be harmless -- the `fstrim`
fails immediately with an obvious error if the device doesn't support it:
`fstrim: ioctl 0xc0185879 failed: Not supported`.

Signed-off-by: David Scott <dave.scott@docker.com>
2016-12-06 12:03:26 +00:00
Justin Cormack
50860750d6 Merge pull request #843 from justincormack/rc3
Update Docker to 1.13.0-rc3
2016-12-05 21:12:20 -08:00
Justin Cormack
5503a0c966 Update Docker to 1.13.0-rc3
Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-05 20:31:16 -08:00
Nathan LeClaire
3a4c93118c Merge pull request #746 from justincormack/no-2375
Stop Docker listening on port 2375
2016-12-05 13:43:36 -08:00
Riyaz Faizullabhoy
0b4f1ab5f4 Disable kexec load in sysctl config
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-05 09:26:17 -08:00
Justin Cormack
1db219717c Merge pull request #834 from nathanleclaire/bump_beta12_digest
Bump digest and re-add DOCKER_FOR_IAAS_VERSION for Azure
2016-12-03 01:19:47 -08:00
French Ben
2954bcf1c7 Added docker image for VHD utils
Signed-off-by: French Ben <frenchben@docker.com>
2016-12-02 20:48:59 -08:00
Nathan LeClaire
9d86c3d1c8 Bump digest and re-add DOCKER_FOR_IAAS_VERSION for Azure
Signed-off-by: Nathan LeClaire <nathan.leclaire@gmail.com>
2016-12-02 18:30:33 -08:00
Justin Cormack
733ebcbee2 Merge pull request #831 from justincormack/split-containers
Split the initrd into base and containers
2016-12-02 10:19:03 -08:00
Justin Cormack
e17ff361ee Split the initrd into base and containers
In future this will allow easier customisation of the containers
for each edition.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 18:13:45 +00:00
Justin Cormack
0cdb8e7a84 Merge pull request #762 from simonferquel/vsudd_dontretry_on_dockerd
[vsudd] Don't retry when dockerd is not running
2016-12-02 08:23:23 -08:00
Justin Cormack
7c8effebbc Merge pull request #830 from justincormack/initrd-align-4
Align compressed initrd to 4 bytes
2016-12-02 08:14:36 -08:00
Justin Cormack
b6cb412309 Align compressed initrd to 4 bytes
Allows appending another initrd.

Also build initrd on tmpfs as should be a bit faster now we have to do
another copy.

Fix #618

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 16:05:49 +00:00
Justin Cormack
bc121d1479 Merge pull request #829 from justincormack/linuxup
Update to Linux 4.8.12
2016-12-02 06:52:22 -08:00
Justin Cormack
b2d3e6fa4a Merge pull request #828 from justincormack/azure-quoting
Missing quote in azure init script
2016-12-02 06:12:54 -08:00
Justin Cormack
9352523bdb Update to Linux 4.8.12
- security update

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 14:12:06 +00:00
Justin Cormack
e09bf4cb73 Merge pull request #827 from justincormack/container-rngd
Run rngd inside a system container
2016-12-02 06:07:46 -08:00
Justin Cormack
f247551d52 Missing quote in azure init script
Fix #826

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 14:03:21 +00:00
Justin Cormack
bf1c21e045 Run rngd inside a system container
- this needs an init as it does not respond to stop signals, so include tini
- needs CAP_SYS_ADMIN to write to kernel entropy estimate
- set kernel.random.write_wakeup_threshold so that rngd does not need sysctl write access
- build patches from Alpine, but statically linked
- remove rngd from base image, means we no longer need community repository

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 14:00:12 +00:00
Justin Cormack
89efaa4fe7 Merge pull request #825 from justincormack/go-up
Update to Go 1.7.4
2016-12-02 01:59:39 -08:00
Justin Cormack
79e6f8c95d Update to Go 1.7.4
Security update.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-02 09:51:36 +00:00
Justin Cormack
c0a795d48b Merge pull request #819 from riyazdf/lynis-sysctl-changes
Add sysctl changes as suggested by lynis
2016-12-02 01:30:55 -08:00
Justin Cormack
39140866aa Merge pull request #824 from riyazdf/bump-waalinux-opensslconfig
Bump windows azure linux agent to include openssl config swapping logic
2016-12-02 01:29:06 -08:00
Riyaz Faizullabhoy
cb1ebba19d Bump windows azure linux agent to include openssl config swapping logic
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-01 19:15:50 -08:00
Riyaz Faizullabhoy
fdffacd809 Add sysctl changes as suggested by lynis
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-01 15:41:57 -08:00
Justin Cormack
116179c895 Merge pull request #820 from riyazdf/digests-and-trust
Use digests for external images and scripts where possible
2016-12-01 12:57:32 -08:00
Justin Cormack
1241b45a49 Merge pull request #822 from riyazdf/dct-in-pull
Use DCT in library/docker run command
2016-12-01 10:34:33 -08:00
Riyaz Faizullabhoy
8b7cdd41dc Use digests instead of tags where possible
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-01 09:39:02 -08:00
Riyaz Faizullabhoy
49a2fc6017 Use DCT in library run command
Signed-off-by: Riyaz Faizullabhoy <riyaz.faizullabhoy@docker.com>
2016-12-01 09:27:01 -08:00
Justin Cormack
1b99ca2dd1 Merge pull request #821 from justincormack/binfmt-cleanup
Makefile cleanup for binfmt
2016-12-01 07:30:09 -08:00
Justin Cormack
8b77e988b5 Makefile cleanup for binfmt
Remove duplication and simplify.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-12-01 15:23:03 +00:00
Nathan LeClaire
73114489b2 Merge pull request #788 from justincormack/small-ami
Use a 1G AMI
2016-11-30 16:22:41 -08:00
Justin Cormack
b3449518d5 Merge pull request #817 from justincormack/content-trust
Use DOCKER_CONTENT_TRUST=1 when pulling library images
2016-11-30 05:40:56 -08:00
Justin Cormack
ea4809a647 Use DOCKER_CONTENT_TRUST=1 when pulling library images
When building the base images always test signatures.

This will be the default at some point.

Add a test that content trust is working.

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-11-30 13:35:38 +00:00
Justin Cormack
f9d44e251e Merge pull request #815 from justincormack/binfmt-container
Containerize binfmt_misc
2016-11-30 05:33:38 -08:00
Justin Cormack
3e6301f501 Containerize binfmt_misc
- statically make containerd symlinks so rootfs can be read only
- run binfmt_misc in a containerd container
- ship arm, aarch64, ppc64le qemu static versions that always "just work" as this is supported in Linux 4.8

fix #53

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
2016-11-30 12:49:37 +00:00
Simon Ferquel
2287d5d7d2 Redirect vsudd stdout/stderr to console
Signed-off-by: Simon Ferquel <simon.ferquel@docker.com>
2016-11-30 10:31:11 +01:00
Simon Ferquel
d40570f976 [vsudd] Don't retry when dockerd is not running
Signed-off-by: Simon Ferquel <simon.ferquel@docker.com>
2016-11-30 10:31:11 +01:00