mirror of
https://github.com/linuxkit/linuxkit.git
synced 2025-12-25 10:12:31 +00:00
NOTE: This will be a shared mount, due to root being turned into a
shared with `MC_REC` set: `mount("", "/", "", rec|shared, "")`.
For some reason setting `shared` when mounting `/sys/fs/bpf` doesn't
work at all, perhaps that's just a kernel feature.
Signed-off-by: Ilya Dmitrichenko <errordeveloper@gmail.com>
44 lines
1.6 KiB
YAML
44 lines
1.6 KiB
YAML
kernel:
|
|
image: linuxkit/kernel:5.4.30
|
|
cmdline: "console=tty0 console=ttyS0"
|
|
init:
|
|
- linuxkit/init:e93b0bf37b030238d33e04b98e90d087637f3d2c
|
|
- linuxkit/runc:f79954950022fea76b8b6f10de58cb48e4fb3878
|
|
- linuxkit/containerd:6ef473a228db6f6ee163f9b9a051102a1552a4ef
|
|
- linuxkit/ca-certificates:abfc6701b9ca17e34ac9439ce5946a247e720ff5
|
|
onboot:
|
|
- name: sysctl
|
|
image: linuxkit/sysctl:541f60fe3676611328e89e8bac251fc636b1a6aa
|
|
- name: dhcpcd
|
|
image: linuxkit/dhcpcd:2f8a9b670aa6e96a09db56ec45c9f07ef2a811ee
|
|
command: ["/sbin/dhcpcd", "--nobackground", "-f", "/dhcpcd.conf", "-1"]
|
|
- name: format
|
|
image: linuxkit/format:0b75e494eea0312f3015e6c6f7c5927620d56c96
|
|
command: ["/usr/bin/format", "/dev/sda"]
|
|
- name: dm-crypt
|
|
image: linuxkit/dm-crypt:0ea63bfd97b719d185b69994b4856d97fbc8a2dd
|
|
command: ["/usr/bin/crypto", "crypt_dev", "/dev/sda1"]
|
|
- name: mount
|
|
image: linuxkit/mount:19fa297189166206ac97261679c3e31fb140d48f
|
|
command: ["/usr/bin/mountie", "/dev/mapper/crypt_dev", "/var/secure_storage"]
|
|
- name: bbox
|
|
image: busybox
|
|
command: ["sh", "-c", "echo 'secret things' >/var/secure_storage/secrets"]
|
|
binds:
|
|
- /var:/var
|
|
services:
|
|
- name: getty
|
|
image: linuxkit/getty:48f66df198981e692084bf70ab72b9fe2be0f880
|
|
env:
|
|
- INSECURE=true
|
|
- name: rngd
|
|
image: linuxkit/rngd:7fab61cca793113280397dcee8159f35dc37adcb
|
|
files:
|
|
- path: etc/dm-crypt/key
|
|
# the below key is just to keep the example self-contained
|
|
# !!! provide a proper key for production use here !!!
|
|
contents: "abcdefghijklmnopqrstuvwxyz123456"
|
|
trust:
|
|
org:
|
|
- linuxkit
|