mirror of
				https://github.com/linuxkit/linuxkit.git
				synced 2025-10-31 02:39:07 +00:00 
			
		
		
		
	Instead of mounting a new filesystem, revert to doing a `rw` bind. However do not make `/` `rshared`, just `/var` as that is where we expect filesystems to be mounted for persistence. Also only make the actual container rootfs writeable, not the whole directory. Signed-off-by: Justin Cormack <justin.cormack@docker.com>
		
			
				
	
	
		
			77 lines
		
	
	
		
			1.9 KiB
		
	
	
	
		
			YAML
		
	
	
	
	
	
			
		
		
	
	
			77 lines
		
	
	
		
			1.9 KiB
		
	
	
	
		
			YAML
		
	
	
	
	
	
| kernel:
 | |
|   image: "mobylinux/kernel:4.9.x"
 | |
|   cmdline: "console=ttyS0 page_poison=1"
 | |
| init:
 | |
|   - mobylinux/init:671bdce1ed0803daeb35e83e4bcd576bb449ea35
 | |
|   - mobylinux/runc:b0fb122e10dbb7e4e45115177a61a3f8d68c19a9
 | |
|   - mobylinux/containerd:c7f6ecdcbcb615a53edee556ba03c7c873bc8488
 | |
|   - mobylinux/ca-certificates:eabc5a6e59f05aa91529d80e9a595b85b046f935
 | |
| onboot:
 | |
|   - name: sysctl
 | |
|     image: "mobylinux/sysctl:2cf2f9d5b4d314ba1bfc22b2fe931924af666d8c"
 | |
|     net: host
 | |
|     pid: host
 | |
|     ipc: host
 | |
|     capabilities:
 | |
|      - CAP_SYS_ADMIN
 | |
|     readonly: true
 | |
|   - name: metadata-gcp
 | |
|     image: "mobylinux/metadata-gcp:7fc3dd5ef92e0408fb3f76048bbaae88bbb55ad9"
 | |
|     binds:
 | |
|      - /tmp:/etc/ssh
 | |
|      - /etc/resolv.conf:/etc/resolv.conf
 | |
|     readonly: true
 | |
|     net: host
 | |
|     uts: host
 | |
|     capabilities:
 | |
|      - CAP_SYS_ADMIN
 | |
| services:
 | |
|   - name: rngd
 | |
|     image: "mobylinux/rngd:3dad6dd43270fa632ac031e99d1947f20b22eec9@sha256:1c93c1db7196f6f71f8e300bc1d15f0376dd18e8891c8789d77c8ff19f3a9a92"
 | |
|     capabilities:
 | |
|      - CAP_SYS_ADMIN
 | |
|     oomScoreAdj: -800
 | |
|     readonly: true
 | |
|   - name: dhcpcd
 | |
|     image: "mobylinux/dhcpcd:3eb32da7ff8051f61e0f18edd90dd0fbfcf148ea"
 | |
|     binds:
 | |
|      - /var:/var
 | |
|      - /tmp:/etc
 | |
|     capabilities:
 | |
|      - CAP_NET_ADMIN
 | |
|      - CAP_NET_BIND_SERVICE
 | |
|      - CAP_NET_RAW
 | |
|     net: host
 | |
|     oomScoreAdj: -800
 | |
|   - name: sshd
 | |
|     image: "mobylinux/sshd:160631d59fffc13d523ff7f09b3b49538d34b9cd"
 | |
|     capabilities:
 | |
|      - all
 | |
|     net: host
 | |
|     pid: host
 | |
|     binds:
 | |
|      - /tmp/authorized_keys:/root/.ssh/authorized_keys
 | |
|      - /etc/resolv.conf:/etc/resolv.conf
 | |
|   - name: nginx
 | |
|     image: "nginx:alpine"
 | |
|     capabilities:
 | |
|      - CAP_NET_BIND_SERVICE
 | |
|      - CAP_CHOWN
 | |
|      - CAP_SETUID
 | |
|      - CAP_SETGID
 | |
|      - CAP_DAC_OVERRIDE
 | |
|     net: host
 | |
| trust:
 | |
|   image:
 | |
|     - mobylinux/kernel
 | |
| files:
 | |
|   - path: etc/docker/daemon.json
 | |
|     contents: '{"debug": true}'
 | |
| outputs:
 | |
|   - format: kernel+initrd
 | |
|   - format: gcp
 | |
|     project: moby
 | |
|     bucket: mobytestjustin
 | |
|     family: moby-dev
 | |
|     replace: true
 |