Justin Cormack
599f2d6f5b
Update yaml files with new init
...
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-30 14:15:16 +01:00
Rolf Neugebauer
8cff978fab
Update YAML files with updated binfmt package
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-05-29 17:30:57 +01:00
Rolf Neugebauer
b70410a478
Update YAML files to updated metadata package
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-05-29 17:30:57 +01:00
Riyaz Faizullabhoy
42c2333fa1
Merge pull request #1915 from tych0/wireguard-fixups
...
Wireguard fixups
2017-05-26 16:12:49 -07:00
Tycho Andersen
4501627923
wireguard: trust everything from linuxkit org
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 16:11:09 -06:00
Tycho Andersen
336d92de3b
wireguard-tools: use linuxkit/alpine as base image
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:55:33 -06:00
Tycho Andersen
8c96d38ca3
wireguard tools: use ORG pattern as in other makefiles
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:45:41 -06:00
Tycho Andersen
2b8756ac16
ima-namespacing utils: use ORG pattern as in other makefiles
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:43:59 -06:00
Tycho Andersen
a53e251908
wireguard: update kernel build
...
We were pointing to the old mobylinux docker hub repo. Let's update the
kernel build to be the new style one.
Note that I didn't bump the kernel version or update the patches at all. We
should do this soon, but for the purposes of our probational channel PoC,
I'm leaving wireguard at the old version for now.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:35:32 -06:00
Tycho Andersen
ddf333685c
wireguard project: s/kernel-wireguard/kernel
...
-wireguard is redundant, and with a standardized name, we can merge patches
"automatically", for our probational channel.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:35:32 -06:00
Tycho Andersen
d6d9a696ad
wireguard project: move to new-style init
...
Rather than re-build the whole init, let's just include the wireguard tools
in a tools repo.
This also moves *most* of the stuff to new linuxkit infrastructure, instead
of the legacy mobylinux. And checks an item off the TODO list.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 15:35:31 -06:00
Tycho Andersen
26d0dc20ec
ima-namespace: use images that actually exist
...
We have a linuxkit/{kernel-ima,ima-utils} now, let's use the images that
are uploaded there!
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 14:48:39 -06:00
Tycho Andersen
06d7157e3c
ima-namespace: only build utils if it doesn't exist
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 14:31:38 -06:00
Tycho Andersen
4a69a57557
ima namespace project: account for new -output in moby tool
...
The moby tool requires us to specify outputs on invocation. Let's do that.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-26 14:27:59 -06:00
Rolf Neugebauer
9bdfcb5b12
Update YAML files with new packages, config, and trust data
...
- Update to packages using the Alpine 3.6 base image
- Remove config for packages which now supply it
- Update/add trust section
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-05-26 16:23:55 +01:00
Justin Cormack
00737bd859
Remove outputs from the yaml files
...
The latest version of the `moby` tool now requires that the output formats
be specified in the CLI not in the yaml file.
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-26 13:55:06 +01:00
Justin Cormack
8d97247d8c
Merge pull request #1877 from tych0/real-kernel-config-impl
...
kernel-config project: add a real implementation of kernel configs
2017-05-24 16:16:33 +01:00
Rolf Neugebauer
ae5dfc6d7d
Update all YAML files to use the new binfmt, dhcpcd and rngd packages
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-05-23 15:55:40 +01:00
Tycho Andersen
ef4bd01de8
kernel-config project: add draft of kernel configs
...
The kernel configs themselves are stored as diffs of what we want vs. each
version's defconfig.
Thus, things like e.g. CONFIG_DEVKMEM drop out after it was made
non-default. The implication of this is (I hope) that as upstream adopts
security features, our delta can shrink (or more realistically, only
include the next-next gen features).
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-22 17:51:09 -06:00
Tycho Andersen
d6269d8504
kernel-config project: add kcimport script
...
This is the script I used with [1] to generate the config diffs and
separate out the arch specific bits. Included mostly just so people can
play around with it if they want to generate their own diffs.
[1]: https://github.com/ulfalizer/Kconfiglib
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-22 16:58:50 -06:00
Tycho Andersen
8a140cefd8
projects: update list of kernels in kernel-config
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-22 16:58:50 -06:00
Tycho Andersen
ee4d74aca6
projects: be more clever about merging kernel config
...
In particular, let's start with a defconfig and edit it, rather than try to
generate the config entirely from our own diff.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-22 16:58:50 -06:00
Tycho Andersen
e60f9d3946
projects: run check-kernel-config.sh at kernel build time
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-22 16:58:50 -06:00
Rolf Neugebauer
a6d834ddf0
Merge pull request #1865 from justincormack/go-compile
...
more Go compile fixes
2017-05-21 11:18:45 +01:00
Rolf Neugebauer
4377ae3209
Merge pull request #1861 from justincormack/containerd-build
...
Update containerd
2017-05-21 11:13:07 +01:00
Justin Cormack
e52bf2f745
Update sysctl and sysfs in yaml files
...
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-20 11:16:48 +01:00
Justin Cormack
702ad5d9d9
Update git hashes for sysctl
...
And remove all the config options as they are now in the label.
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-19 22:05:15 +01:00
Justin Cormack
a3ea4646e5
Update containerd in yaml files
...
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-19 11:52:12 +01:00
Justin Cormack
ac31862c42
Merge pull request #1857 from tych0/add-ima-project
...
projects: add IMA namespacing project
2017-05-18 22:12:02 +01:00
Tycho Andersen
3fd6337a45
ima: use ima-utils package instead of new init
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-18 13:44:04 -06:00
Tycho Andersen
4b29c738e0
projects: add a blurb about ima namespacing
...
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-18 13:43:59 -06:00
Tycho Andersen
d80e880f28
projects: add IMA namespacing project
...
This is a project with a v1 of the IMA namespacing patches. See the readme
for details on use.
Signed-off-by: Tycho Andersen <tycho@docker.com >
2017-05-18 12:25:07 -06:00
Rolf Neugebauer
6bea56c185
Update all YAML files to use the new packages
...
Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com >
2017-05-18 18:55:22 +01:00
Justin Cormack
5eff65a688
Merge pull request #1818 from jadametz/fix-1817
...
Specifies root user in projects/kubernetes ssh_into_kubelet script
2017-05-13 10:21:56 +01:00
Jesse Adametz
547e2dca95
Specifies root user in projects/kubernetes ssh_into_kubelet script
...
Signed-off-by: Jesse Adametz <jesseadametz@gmail.com >
2017-05-12 15:17:26 -07:00
Justin Cormack
60500940ab
Merge pull request #1816 from ijc25/swarmd
...
projects/swarmd: Updates
2017-05-12 23:06:21 +01:00
Jesse Adametz
2ece5ac28a
Add rm flag to projects/kubernetes ssh script
...
Signed-off-by: Jesse Adametz <jesseadametz@gmail.com >
2017-05-12 14:25:18 -07:00
Ian Campbell
0fb3d1c6e9
Updated swarmd commit
...
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:48:52 +01:00
Ian Campbell
a28d34f18c
Modernise swarmd pkg build
...
Uses multi stage builds and the tree-sh as tag.
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:48:01 +01:00
Ian Campbell
5eee4c0607
pkg/runc: WORKDIR as first item in second stage
...
Works around https://github.com/moby/moby/issues/33176 and fixes #1807 .
Updated al users of linuxkit/runc:2649198589ef0020d99f613adaeda45ce0093a38 to
this new build.
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:23:27 +01:00
Ian Campbell
1b31a0ea3b
swarmd: Mount persistent disk on /var/lib/swarmd
...
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:11:45 +01:00
Ian Campbell
14b0c00133
swarmd: Switch to oneshot DHCP
...
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:11:45 +01:00
Ian Campbell
6c87493ec5
swarmd: Add metadata service
...
Also update other users of linuxkit/metadata to the newest build while I'm
here.
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:10:49 +01:00
Ian Campbell
5b0f92fb9e
swarmd: Update to latest images (from linuxkit.yml)
...
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:02:25 +01:00
Ian Campbell
f5732b2cb5
swarmd: Add ntpd
...
Follows https://github.com/docker/moby/pull/1576
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:02:25 +01:00
Ian Campbell
8e90e67eea
swarmd: host pid namespace for CNI access to /proc/PID/ns/net
...
Since containers are spawned by containerd (which is in the host PID namespace)
and not in the swarmd container's namespace.
Signed-off-by: Ian Campbell <ian.campbell@docker.com >
2017-05-12 19:02:23 +01:00
Justin Cormack
6a5f8099a4
Remove extra files from init
...
fix #1807
Signed-off-by: Justin Cormack <justin.cormack@docker.com >
2017-05-12 15:36:13 +01:00
Magnus Skjegstad
1da0b14e23
logging: update example to use latest init/containerd
...
Signed-off-by: Magnus Skjegstad <magnus@skjegstad.com >
2017-05-11 21:08:23 +02:00
Magnus Skjegstad
37ddf42b5b
logging: add log capture to onboot and service startup
...
Signed-off-by: Magnus Skjegstad <magnus@skjegstad.com >
2017-05-11 21:07:58 +02:00
Magnus Skjegstad
4a9a5afd03
logging: update init scripts to latest version with containerd
...
Signed-off-by: Magnus Skjegstad <magnus@skjegstad.com >
2017-05-11 20:59:55 +02:00