Compare commits
9 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2510e98b37 | ||
|
|
ab98aa7a0b | ||
|
|
83e09798b2 | ||
|
|
f49ace8371 | ||
|
|
dba5d017c8 | ||
|
|
72de8d4dca | ||
|
|
12ff348c8c | ||
|
|
5454857d03 | ||
|
|
5e065a4c2e |
5 changed files with 18 additions and 22 deletions
13
Dockerfile
13
Dockerfile
|
|
@ -1,8 +1,8 @@
|
||||||
FROM registry.fedoraproject.org/fedora:rawhide
|
FROM registry.fedoraproject.org/fedora:26
|
||||||
|
|
||||||
ENV VERSION=0 RELEASE=1 ARCH=x86_64
|
ENV VERSION=0 RELEASE=9 ARCH=x86_64
|
||||||
LABEL com.redhat.component="docker" \
|
LABEL com.redhat.component="docker" \
|
||||||
name="docker" \
|
name="$FGC/docker" \
|
||||||
version="$VERSION" \
|
version="$VERSION" \
|
||||||
release="$RELEASE.$DISTTAG" \
|
release="$RELEASE.$DISTTAG" \
|
||||||
architecture="$ARCH" \
|
architecture="$ARCH" \
|
||||||
|
|
@ -13,7 +13,8 @@ LABEL com.redhat.component="docker" \
|
||||||
|
|
||||||
RUN dnf install --setopt=tsflags=nodocs -y docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \
|
RUN dnf install --setopt=tsflags=nodocs -y docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \
|
||||||
&& rpm -V docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \
|
&& rpm -V docker container-storage-setup container-selinux cloud-utils-growpart python-docker-py docker-novolume-plugin lvm2 iptables procps-ng xz oci-register-machine \
|
||||||
&& mkdir -p /usr/lib/modules && dnf clean all
|
&& mkdir -p /usr/lib/modules /exports/hostfs/etc/docker \
|
||||||
|
&& dnf clean all
|
||||||
|
|
||||||
RUN ln -s /usr/libexec/docker/docker-runc-current /usr/bin/docker-runc
|
RUN ln -s /usr/libexec/docker/docker-runc-current /usr/bin/docker-runc
|
||||||
|
|
||||||
|
|
@ -25,6 +26,8 @@ COPY set_mounts.sh /
|
||||||
COPY config.json.template service.template tmpfiles.template /exports/
|
COPY config.json.template service.template tmpfiles.template /exports/
|
||||||
COPY daemon.json /exports/hostfs/etc/docker/container-daemon.json
|
COPY daemon.json /exports/hostfs/etc/docker/container-daemon.json
|
||||||
# https://github.com/rhatdan/oci-umount/issues/2
|
# https://github.com/rhatdan/oci-umount/issues/2
|
||||||
RUN cp /etc/oci-umount.conf /exports/hostfs/etc
|
# Copy config if available
|
||||||
|
RUN (test -e /etc/oci-umount.conf && cp /etc/oci-umount.conf /exports/hostfs/etc) || true
|
||||||
|
|
||||||
|
|
||||||
CMD ["/usr/bin/init.sh"]
|
CMD ["/usr/bin/init.sh"]
|
||||||
|
|
|
||||||
|
|
@ -5,6 +5,7 @@
|
||||||
"arch": "amd64"
|
"arch": "amd64"
|
||||||
},
|
},
|
||||||
"process": {
|
"process": {
|
||||||
|
"selinuxLabel": "system_u:system_r:container_runtime_t:s0",
|
||||||
"terminal": false,
|
"terminal": false,
|
||||||
"user": {
|
"user": {
|
||||||
"uid": 0,
|
"uid": 0,
|
||||||
|
|
@ -294,17 +295,6 @@
|
||||||
"mode=755"
|
"mode=755"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
|
||||||
"type": "bind",
|
|
||||||
"source": "/usr/share/rhel",
|
|
||||||
"destination": "/usr/share/rhel",
|
|
||||||
"options": [
|
|
||||||
"rprivate",
|
|
||||||
"rbind",
|
|
||||||
"ro",
|
|
||||||
"mode=755"
|
|
||||||
]
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
"type": "bind",
|
"type": "bind",
|
||||||
"source": "${RUN_DIRECTORY}",
|
"source": "${RUN_DIRECTORY}",
|
||||||
|
|
@ -380,7 +370,7 @@
|
||||||
],
|
],
|
||||||
"hooks": {},
|
"hooks": {},
|
||||||
"linux": {
|
"linux": {
|
||||||
"rootfsPropagation": "private",
|
"rootfsPropagation": "rslave",
|
||||||
"resources": {
|
"resources": {
|
||||||
"devices": [
|
"devices": [
|
||||||
{
|
{
|
||||||
|
|
@ -393,7 +383,6 @@
|
||||||
{
|
{
|
||||||
"type": "mount"
|
"type": "mount"
|
||||||
}
|
}
|
||||||
],
|
]
|
||||||
"selinuxProcessLabel": "system_u:system_r:container_runtime_t:s0"
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,4 @@
|
||||||
|
|
||||||
{
|
{
|
||||||
"authorization-plugins": ["rhel-push-plugin"],
|
|
||||||
"default-runtime": "oci",
|
"default-runtime": "oci",
|
||||||
"containerd": "/run/containerd.sock",
|
"containerd": "/run/containerd.sock",
|
||||||
"userland-proxy-path": "/usr/libexec/docker/docker-proxy-current",
|
"userland-proxy-path": "/usr/libexec/docker/docker-proxy-current",
|
||||||
|
|
|
||||||
7
init.sh
7
init.sh
|
|
@ -1,5 +1,10 @@
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
|
|
||||||
|
# Ensure that new process maintain this SELinux label
|
||||||
|
PID=$$
|
||||||
|
LABEL=`tr -d '\000' < /proc/$PID/attr/current`
|
||||||
|
printf %s $LABEL > /proc/self/attr/exec
|
||||||
|
|
||||||
source /run/docker-bash-env
|
source /run/docker-bash-env
|
||||||
|
|
||||||
# set storage first
|
# set storage first
|
||||||
|
|
@ -22,7 +27,7 @@ do
|
||||||
sleep 0.1
|
sleep 0.1
|
||||||
done
|
done
|
||||||
|
|
||||||
# Run all the installed containers
|
# Run all the installed plugins
|
||||||
mkdir -p /run/docker/plugins/
|
mkdir -p /run/docker/plugins/
|
||||||
ls -1 /usr/libexec/docker/*plugin | \
|
ls -1 /usr/libexec/docker/*plugin | \
|
||||||
while read i;
|
while read i;
|
||||||
|
|
|
||||||
|
|
@ -6,6 +6,7 @@ After=network.target
|
||||||
EnvironmentFile=-/etc/sysconfig/docker-storage
|
EnvironmentFile=-/etc/sysconfig/docker-storage
|
||||||
EnvironmentFile=-/etc/sysconfig/docker-network
|
EnvironmentFile=-/etc/sysconfig/docker-network
|
||||||
Environment=GOTRACEBACK=crash
|
Environment=GOTRACEBACK=crash
|
||||||
|
SELinuxContext=system_u:system_r:container_runtime_t:s0
|
||||||
ExecStartPre=/bin/sh $DESTDIR/rootfs/set_mounts.sh
|
ExecStartPre=/bin/sh $DESTDIR/rootfs/set_mounts.sh
|
||||||
ExecStartPre=/bin/bash -c 'export -p > /run/docker-bash-env'
|
ExecStartPre=/bin/bash -c 'export -p > /run/docker-bash-env'
|
||||||
ExecStart=$EXEC_START
|
ExecStart=$EXEC_START
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue