diff --git a/Dockerfile b/Dockerfile index 377bf7c..bbbaa6e 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,18 +1,17 @@ -FROM registry.fedoraproject.org/fedora:25 +FROM registry.fedoraproject.org/fedora:rawhide -ENV VERSION=0 RELEASE=8 ARCH=x86_64 +ENV VERSION=0 ARCH=x86_64 LABEL com.redhat.component="docker" \ - name="$FGC/docker" \ + name="docker" \ version="$VERSION" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ usage="atomic install --system --system-package=no docker && systemctl start docker" \ summary="The docker daemon as a system container." \ maintainer="Giuseppe Scrivano " \ atomic.type="system" -RUN dnf install --setopt=tsflags=nodocs -y docker container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ - && rpm -V docker container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ +RUN dnf install --setopt=tsflags=nodocs -y docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ + && rpm -V docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \ && mkdir -p /usr/lib/modules && dnf clean all RUN ln -s /usr/libexec/docker/docker-runc-current /usr/bin/docker-runc @@ -25,6 +24,6 @@ COPY set_mounts.sh / COPY config.json.template service.template tmpfiles.template /exports/ COPY daemon.json /exports/hostfs/etc/docker/container-daemon.json # https://github.com/rhatdan/oci-umount/issues/2 -RUN (test -e /etc/oci-umount.conf && cp /etc/oci-umount.conf /exports/hostfs/etc) || true +RUN cp /etc/oci-umount.conf /exports/hostfs/etc CMD ["/usr/bin/init.sh"] diff --git a/config.json.template b/config.json.template index cd433c3..3ce615c 100644 --- a/config.json.template +++ b/config.json.template @@ -5,7 +5,6 @@ "arch": "amd64" }, "process": { - "selinuxLabel": "system_u:system_r:container_runtime_t:s0", "terminal": false, "user": { "uid": 0, @@ -394,6 +393,7 @@ { "type": "mount" } - ] + ], + "selinuxProcessLabel": "system_u:system_r:container_runtime_t:s0" } } diff --git a/daemon.json b/daemon.json index 445fe8a..ea5e789 100644 --- a/daemon.json +++ b/daemon.json @@ -1,4 +1,6 @@ + { + "authorization-plugins": ["rhel-push-plugin"], "default-runtime": "oci", "containerd": "/run/containerd.sock", "userland-proxy-path": "/usr/libexec/docker/docker-proxy-current", diff --git a/init.sh b/init.sh index 4347c47..ac03b38 100755 --- a/init.sh +++ b/init.sh @@ -1,10 +1,5 @@ #!/bin/bash -# Ensure that new process maintain this SELinux label -PID=$$ -LABEL=`tr -d '\000' < /proc/$PID/attr/current` -printf %s $LABEL > /proc/self/attr/exec - source /run/docker-bash-env # set storage first @@ -27,7 +22,7 @@ do sleep 0.1 done -# Run all the installed plugins +# Run all the installed containers mkdir -p /run/docker/plugins/ ls -1 /usr/libexec/docker/*plugin | \ while read i;