mirror of
https://github.com/linuxkit/linuxkit.git
synced 2025-10-26 20:27:00 +00:00
Works around https://github.com/moby/moby/issues/33176 and fixes #1807. Updated al users of linuxkit/runc:2649198589ef0020d99f613adaeda45ce0093a38 to this new build. Signed-off-by: Ian Campbell <ian.campbell@docker.com>
120 lines
3.2 KiB
YAML
120 lines
3.2 KiB
YAML
kernel:
|
|
image: "linuxkit/kernel:4.9.x"
|
|
cmdline: "console=ttyS0 console=tty0 page_poison=1"
|
|
init:
|
|
- linuxkit/init:b3740303f3d1e5689a84c87b7dfb48fd2a40a192
|
|
- linuxkit/runc:47b1c38d63468c0f3078f8b1b055d07965a1895d
|
|
- linuxkit/containerd:cf2614f5a96c569a0bd4bd54e054a65ba17d167f
|
|
- linuxkit/ca-certificates:3344cdca1bc59fdfa17bd7f0fcbf491b9dbaa288
|
|
onboot:
|
|
- name: sysctl
|
|
image: "linuxkit/sysctl:1f5ec5d5e6f7a7a1b3d2ff9dd9e36fd6fb14756a"
|
|
net: host
|
|
pid: host
|
|
ipc: host
|
|
capabilities:
|
|
- CAP_SYS_ADMIN
|
|
readonly: true
|
|
- name: sysfs
|
|
image: linuxkit/sysfs:6c1d06f28ddd9681799d3950cddf044b930b221c
|
|
- name: binfmt
|
|
image: "linuxkit/binfmt:131026c0cf6084467316395fed3b358f64bda00c"
|
|
binds:
|
|
- /proc/sys/fs/binfmt_misc:/binfmt_misc
|
|
readonly: true
|
|
- name: format
|
|
image: "linuxkit/format:d78093e943f9c88386e30c00353f9476d34fb551"
|
|
binds:
|
|
- /dev:/dev
|
|
capabilities:
|
|
- CAP_SYS_ADMIN
|
|
- CAP_MKNOD
|
|
- name: mounts
|
|
image: "linuxkit/kubernetes:latest-mounts"
|
|
capabilities:
|
|
- all
|
|
pid: host
|
|
rootfsPropagation: shared
|
|
binds:
|
|
- /dev:/dev
|
|
- /var:/var:rshared,rbind
|
|
services:
|
|
- name: rngd
|
|
image: "linuxkit/rngd:f5e5be43e730ea819c3293d5c6dcbfa7f4c5c314"
|
|
capabilities:
|
|
- CAP_SYS_ADMIN
|
|
oomScoreAdj: -800
|
|
readonly: true
|
|
- name: dhcpcd
|
|
image: "linuxkit/dhcpcd:2def74ab3f9233b4c09ebb196ba47c27c08b0ed8"
|
|
binds:
|
|
- /var:/var
|
|
- /tmp/etc:/etc
|
|
capabilities:
|
|
- CAP_NET_ADMIN
|
|
- CAP_NET_BIND_SERVICE
|
|
- CAP_NET_RAW
|
|
net: host
|
|
oomScoreAdj: -800
|
|
- name: ntpd
|
|
image: "linuxkit/openntpd:a38eabb308d0405f58894979f8b8031a6c7e1134"
|
|
capabilities:
|
|
- CAP_SYS_TIME
|
|
- CAP_SYS_NICE
|
|
- CAP_SYS_CHROOT
|
|
- CAP_SETUID
|
|
- CAP_SETGID
|
|
net: host
|
|
- name: sshd
|
|
image: "linuxkit/sshd:e108d208adf692c8a0954f602743e0eec445364e"
|
|
capabilities:
|
|
- all
|
|
net: host
|
|
pid: host
|
|
binds:
|
|
- /root/.ssh:/root/.ssh
|
|
- name: docker
|
|
image: "linuxkit/docker-ce:050e734489f2d19b42ec818a4242a318ea446bc3"
|
|
capabilities:
|
|
- all
|
|
net: host
|
|
pid: host
|
|
mounts:
|
|
- type: cgroup
|
|
options: ["rw","nosuid","noexec","nodev","relatime"]
|
|
binds:
|
|
- /dev:/dev
|
|
- /lib/modules:/lib/modules
|
|
- /var:/var:rshared,rbind
|
|
- /var/lib/kubeadm:/etc/kubernetes
|
|
- /etc/cni:/etc/cni:rshared,rbind
|
|
- /opt/cni:/opt/cni:rshared,rbind
|
|
rootfsPropagation: shared
|
|
- name: kubernetes-image-cache-common
|
|
image: "linuxkit/kubernetes:latest-image-cache-common"
|
|
binds:
|
|
- /var/run:/var/run
|
|
- name: kubelet
|
|
image: "linuxkit/kubernetes:latest"
|
|
capabilities:
|
|
- all
|
|
net: host
|
|
pid: host
|
|
mounts:
|
|
- type: cgroup
|
|
options: ["rw","nosuid","noexec","nodev","relatime"]
|
|
binds:
|
|
- /dev:/dev
|
|
- /var:/var:rshared,rbind
|
|
- /var/lib/kubeadm:/etc/kubernetes
|
|
- /etc/cni:/rootfs/etc/cni:rshared,rbind
|
|
- /opt/cni:/rootfs/opt/cni:rshared,rbind
|
|
rootfsPropagation: shared
|
|
files:
|
|
- path: root/.ssh/authorized_keys
|
|
contents: '# Your ssh key goes here'
|
|
- {path: etc/cni, directory: true}
|
|
- {path: opt/cni, directory: true}
|
|
outputs:
|
|
- format: kernel+initrd
|