From b01c536ca3725957cb52b509f825d282b7919696 Mon Sep 17 00:00:00 2001 From: yuqi-zhang Date: Wed, 8 Mar 2017 15:56:50 -0500 Subject: [PATCH 1/3] Initial import (#1421858). --- Dockerfile | 23 +++++ README.md | 52 +++++++++++ config.json.template | 210 +++++++++++++++++++++++++++++++++++++++++++ flanneld-run.sh | 20 +++++ manifest.json | 10 +++ service.template | 20 +++++ tmpfiles.template | 3 + 7 files changed, 338 insertions(+) create mode 100644 Dockerfile create mode 100644 README.md create mode 100644 config.json.template create mode 100755 flanneld-run.sh create mode 100644 manifest.json create mode 100644 service.template create mode 100644 tmpfiles.template diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000..775f445 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,23 @@ +FROM fedora:rawhide + +ENV container=docker FLANNELD_ETCD_ENDPOINTS="http://127.0.0.1:2379" FLANNELD_ETCD_PREFIX="/atomic.io/network" + +ENV VERSION=0.1 RELEASE=2 ARCH=x86_64 +LABEL BZComponent="flannel" \ + Name="$FGC/flannel" \ + Version="$VERSION" \ + Release="$RELEASE.$DISTTAG" \ + Architecture="$ARCH" \ + Summary="An etcd driven address agent, intended to be run as a system container" \ + maintainer="Giuseppe Scrivano " \ + atomic.type='system' + +RUN dnf -y --setopt=tsflags=nodocs install flannel && dnf clean all + +ADD flanneld-run.sh /usr/bin/ + +# System container files +COPY tmpfiles.template service.template manifest.json \ + config.json.template /exports/ + +CMD ["/usr/bin/flanneld-run.sh"] diff --git a/README.md b/README.md new file mode 100644 index 0000000..fb6dbd4 --- /dev/null +++ b/README.md @@ -0,0 +1,52 @@ +# flannel-container + +This container image is intended to be run as a system container +with the atomic command line. + +Building flannel container for fedora and atomic host: + +``` +# git clone https://github.com/projectatomic/atomic-system-containers +# cd atomic-system-containers/flannel +# docker build -t flannel . +``` + +**Running as system container, with the atomic CLI:** + +Prerequisite: + +1. etcd must be running + +2. a network is configured in etcd + +(example with etcd installed as a system container: `runc exec etcd etcdctl set /atomic.io/network/config '{"Network":"172.17.0.0/16"}'`) + +Pull from local docker into ostree: + +``` +#atomic pull --storage ostree docker:flannel +``` + +Install the container: + +``` +#atomic install --system flannel +``` + +Start as a systemd service: + +``` +#systemctl start flannel +``` + +Stopping the service + +``` +#systemctl stop flannel +``` + +Removing the container + +``` +#atomic uninstall flannel +``` diff --git a/config.json.template b/config.json.template new file mode 100644 index 0000000..457dfd6 --- /dev/null +++ b/config.json.template @@ -0,0 +1,210 @@ +{ + "ociVersion": "0.5.0", + "platform": { + "os": "linux", + "arch": "amd64" + }, + "process": { + "terminal": false, + "user": {}, + "args": [ + "/usr/bin/flanneld-run.sh" + ], + "env": [ + "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin", + "FLANNELD_ETCD_PREFIX=$FLANNELD_ETCD_PREFIX", + "FLANNELD_ETCD_ENDPOINTS=$FLANNELD_ETCD_ENDPOINTS", + "TERM=xterm", + "NAME=$NAME" + ], + "cwd": "/", + "capabilities": [ + "CAP_FOWNER", + "CAP_FSETID", + "CAP_KILL", + "CAP_SETGID", + "CAP_SETUID", + "CAP_SETPCAP", + "CAP_LINUX_IMMUTABLE", + "CAP_NET_BIND_SERVICE", + "CAP_NET_BROADCAST", + "CAP_NET_ADMIN", + "CAP_NET_RAW", + "CAP_IPC_LOCK", + "CAP_IPC_OWNER", + "CAP_SYS_MODULE", + "CAP_SYS_RAWIO", + "CAP_SYS_CHROOT", + "CAP_SYS_PTRACE", + "CAP_SYS_PACCT", + "CAP_SYS_ADMIN", + "CAP_SYS_BOOT", + "CAP_SYS_NICE", + "CAP_SYS_RESOURCE", + "CAP_SYS_TIME", + "CAP_SYS_TTY_CONFIG", + "CAP_MKNOD", + "CAP_LEASE", + "CAP_AUDIT_WRITE", + "CAP_AUDIT_CONTROL", + "CAP_SETFCAP", + "CAP_MAC_OVERRIDE", + "CAP_MAC_ADMIN", + "CAP_SYSLOG", + "CAP_WAKE_ALARM", + "CAP_BLOCK_SUSPEND" + ], + "rlimits": [ + { + "type": "RLIMIT_NOFILE", + "hard": 1024, + "soft": 1024 + } + ], + "noNewPrivileges": false + }, + "root": { + "path": "rootfs", + "readonly": true + }, + "hostname": "flannel", + "mounts": [ + { + "destination": "/proc", + "type": "proc", + "source": "proc" + }, + { + "type": "bind", + "source": "/dev", + "destination": "/dev", + "options": [ + "rbind", + "rw", + "mode=755" + ] + }, + { + "destination": "/dev/pts", + "type": "devpts", + "source": "devpts", + "options": [ + "nosuid", + "noexec", + "newinstance", + "ptmxmode=0666", + "mode=0620", + "gid=5" + ] + }, + { + "destination": "/dev/shm", + "type": "tmpfs", + "source": "shm", + "options": [ + "nosuid", + "noexec", + "nodev", + "mode=1777", + "size=65536k" + ] + }, + { + "destination": "/dev/mqueue", + "type": "mqueue", + "source": "mqueue", + "options": [ + "nosuid", + "noexec", + "nodev" + ] + }, + { + "destination": "/sys", + "type": "sysfs", + "source": "sysfs", + "options": [ + "nosuid", + "noexec", + "nodev", + "ro" + ] + }, + { + "destination": "/sys/fs/cgroup", + "type": "cgroup", + "source": "cgroup", + "options": [ + "nosuid", + "noexec", + "nodev", + "relatime", + "ro" + ] + }, + { + "type": "bind", + "source": "/etc/systemd/system/docker.service.d", + "destination": "/etc/systemd/system/docker.service.d", + "options": [ + "rbind", + "rw", + "mode=755" + ] + }, + { + "source": "${RUN_DIRECTORY}/${NAME}", + "destination": "/run/flannel", + "type": "bind", + "options": [ + "rw", + "rbind", + "rprivate" + ] + }, + { + "destination": "/etc/resolv.conf", + "type": "bind", + "source": "/etc/resolv.conf", + "options": [ + "ro", + "rbind", + "rprivate" + ] + } + ], + "hooks": {}, + "linux": { + "resources": { + "devices": [ + { + "allow": false, + "access": "rwm" + } + ] + }, + "namespaces": [ + { + "type": "ipc" + }, + { + "type": "uts" + }, + { + "type": "mount" + } + ], + "maskedPaths": [ + "/proc/kcore", + "/proc/latency_stats", + "/proc/timer_stats", + "/proc/sched_debug" + ], + "readonlyPaths": [ + "/proc/asound", + "/proc/bus", + "/proc/irq", + "/proc/sysrq-trigger" + ] + } +} diff --git a/flanneld-run.sh b/flanneld-run.sh new file mode 100755 index 0000000..5303a90 --- /dev/null +++ b/flanneld-run.sh @@ -0,0 +1,20 @@ +#!/bin/bash + +# Create flannel.conf for docker service +echo "[Service]" > /etc/systemd/system/docker.service.d/$NAME.conf +echo "EnvironmentFile=-/run/$NAME/docker" >> /etc/systemd/system/docker.service.d/$NAME.conf + +# Ensure this file doesn't already exist. +rm -f run/flannel/subnet.env + +/usr/bin/flanneld & +child=$! + +while test \! -e /run/flannel/subnet.env +do + sleep 0.1 +done + +/usr/libexec/flannel/mk-docker-opts.sh -k DOCKER_NETWORK_OPTIONS -d /run/flannel/docker + +wait $child diff --git a/manifest.json b/manifest.json new file mode 100644 index 0000000..816c24e --- /dev/null +++ b/manifest.json @@ -0,0 +1,10 @@ +{ + "version": "1.0", + "defaultValues": { + "FLANNELD_ETCD_PREFIX": "/atomic.io/network", + "FLANNELD_ETCD_ENDPOINTS": "http://127.0.0.1:2379", + "AFTER": "etcd.service", + "REQUIRED_BY": "docker.service" + } +} + diff --git a/service.template b/service.template new file mode 100644 index 0000000..d25dc8c --- /dev/null +++ b/service.template @@ -0,0 +1,20 @@ +[Unit] +Description=Flanneld overlay address etcd agent +After=network.target +After=network-online.target +Wants=network-online.target +After=$AFTER +Before=docker.service + +[Service] +ExecStart=$EXEC_START +ExecStop=$EXEC_STOP +ExecStartPost=/usr/bin/sh -c "while test \! -s ${RUN_DIRECTORY}/${NAME}/docker; do sleep 0.1; done" +ExecStopPost=/bin/rm /etc/systemd/system/docker.service.d/$NAME.conf +Restart=on-failure +WorkingDirectory=$DESTDIR +RuntimeDirectory=${NAME} + +[Install] +WantedBy=multi-user.target +RequiredBy=$REQUIRED_BY diff --git a/tmpfiles.template b/tmpfiles.template new file mode 100644 index 0000000..77acbd8 --- /dev/null +++ b/tmpfiles.template @@ -0,0 +1,3 @@ +D ${RUN_DIRECTORY}/${NAME} - - - - - +d /etc/systemd/system/docker.service.d - - - - - +r /etc/systemd/system/docker.service.d/$NAME.conf - - - - - From b73797c19f1beea74ec4c42f38d0d50d7d405b52 Mon Sep 17 00:00:00 2001 From: yuqi-zhang Date: Wed, 6 Sep 2017 15:21:04 -0400 Subject: [PATCH 2/3] Update master to upstream Signed-off-by: Yu Qi Zhang --- Dockerfile | 19 ++++---- config.json.template | 102 ++++++++++++++++++++++++++----------------- flanneld-run.sh | 6 ++- service.template | 3 +- 4 files changed, 81 insertions(+), 49 deletions(-) diff --git a/Dockerfile b/Dockerfile index 775f445..be9ee85 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,14 +1,14 @@ -FROM fedora:rawhide +FROM registry.fedoraproject.org/fedora:rawhide ENV container=docker FLANNELD_ETCD_ENDPOINTS="http://127.0.0.1:2379" FLANNELD_ETCD_PREFIX="/atomic.io/network" -ENV VERSION=0.1 RELEASE=2 ARCH=x86_64 -LABEL BZComponent="flannel" \ - Name="$FGC/flannel" \ - Version="$VERSION" \ - Release="$RELEASE.$DISTTAG" \ - Architecture="$ARCH" \ - Summary="An etcd driven address agent, intended to be run as a system container" \ +ENV VERSION=0 RELEASE=8 ARCH=x86_64 +LABEL com.redhat.component="flannel" \ + name="$FGC/flannel" \ + version="$VERSION" \ + release="$RELEASE.$DISTTAG" \ + architecture="$ARCH" \ + summary="An etcd driven address agent, intended to be run as a system container" \ maintainer="Giuseppe Scrivano " \ atomic.type='system' @@ -16,6 +16,9 @@ RUN dnf -y --setopt=tsflags=nodocs install flannel && dnf clean all ADD flanneld-run.sh /usr/bin/ +RUN mkdir -p /exports/hostfs/etc/sysconfig/ && cp /etc/sysconfig/flanneld /exports/hostfs/etc/sysconfig/ +RUN mkdir -p /exports/hostfs/etc/flanneld + # System container files COPY tmpfiles.template service.template manifest.json \ config.json.template /exports/ diff --git a/config.json.template b/config.json.template index 457dfd6..e1cae75 100644 --- a/config.json.template +++ b/config.json.template @@ -1,12 +1,15 @@ { - "ociVersion": "0.5.0", + "ociVersion": "1.0.0", "platform": { "os": "linux", "arch": "amd64" }, "process": { "terminal": false, - "user": {}, + "user": { + "uid": 0, + "gid": 0 + }, "args": [ "/usr/bin/flanneld-run.sh" ], @@ -18,42 +21,43 @@ "NAME=$NAME" ], "cwd": "/", - "capabilities": [ - "CAP_FOWNER", - "CAP_FSETID", - "CAP_KILL", - "CAP_SETGID", - "CAP_SETUID", - "CAP_SETPCAP", - "CAP_LINUX_IMMUTABLE", - "CAP_NET_BIND_SERVICE", - "CAP_NET_BROADCAST", - "CAP_NET_ADMIN", - "CAP_NET_RAW", - "CAP_IPC_LOCK", - "CAP_IPC_OWNER", - "CAP_SYS_MODULE", - "CAP_SYS_RAWIO", - "CAP_SYS_CHROOT", - "CAP_SYS_PTRACE", - "CAP_SYS_PACCT", - "CAP_SYS_ADMIN", - "CAP_SYS_BOOT", - "CAP_SYS_NICE", - "CAP_SYS_RESOURCE", - "CAP_SYS_TIME", - "CAP_SYS_TTY_CONFIG", - "CAP_MKNOD", - "CAP_LEASE", - "CAP_AUDIT_WRITE", - "CAP_AUDIT_CONTROL", - "CAP_SETFCAP", - "CAP_MAC_OVERRIDE", - "CAP_MAC_ADMIN", - "CAP_SYSLOG", - "CAP_WAKE_ALARM", - "CAP_BLOCK_SUSPEND" - ], + "capabilities": { + "bounding": [ + "CAP_DAC_READ_SEARCH", + "CAP_AUDIT_WRITE", + "CAP_KILL", + "CAP_NET_BIND_SERVICE", + "CAP_NET_ADMIN" + ], + "permitted": [ + "CAP_DAC_READ_SEARCH", + "CAP_AUDIT_WRITE", + "CAP_KILL", + "CAP_NET_BIND_SERVICE", + "CAP_NET_ADMIN" + ], + "inheritable": [ + "CAP_DAC_READ_SEARCH", + "CAP_AUDIT_WRITE", + "CAP_KILL", + "CAP_NET_BIND_SERVICE", + "CAP_NET_ADMIN" + ], + "effective": [ + "CAP_DAC_READ_SEARCH", + "CAP_AUDIT_WRITE", + "CAP_KILL", + "CAP_NET_BIND_SERVICE", + "CAP_NET_ADMIN" + ], + "ambient": [ + "CAP_DAC_READ_SEARCH", + "CAP_AUDIT_WRITE", + "CAP_KILL", + "CAP_NET_BIND_SERVICE", + "CAP_NET_ADMIN" + ] + }, "rlimits": [ { "type": "RLIMIT_NOFILE", @@ -171,7 +175,27 @@ "rbind", "rprivate" ] - } + }, + { + "source": "/etc/sysconfig/flanneld", + "destination": "/etc/sysconfig/flanneld", + "type": "bind", + "options": [ + "rw", + "rbind", + "rprivate" + ] + }, + { + "source": "/etc/flanneld", + "destination": "/etc/flanneld", + "type": "bind", + "options": [ + "rw", + "rbind", + "rprivate" + ] + } ], "hooks": {}, "linux": { diff --git a/flanneld-run.sh b/flanneld-run.sh index 5303a90..e527d3c 100755 --- a/flanneld-run.sh +++ b/flanneld-run.sh @@ -4,10 +4,12 @@ echo "[Service]" > /etc/systemd/system/docker.service.d/$NAME.conf echo "EnvironmentFile=-/run/$NAME/docker" >> /etc/systemd/system/docker.service.d/$NAME.conf +source /etc/sysconfig/flanneld + # Ensure this file doesn't already exist. rm -f run/flannel/subnet.env -/usr/bin/flanneld & +NOTIFY_SOCKET=/dev/null /usr/bin/flanneld -etcd-endpoints=${FLANNEL_ETCD_ENDPOINTS} -etcd-prefix=${FLANNEL_ETCD_PREFIX} -etcd-cafile=${FLANNEL_ETCD_CAFILE} -etcd-certfile=${FLANNEL_ETCD_CERTFILE} -etcd-keyfile=${FLANNEL_ETCD_KEYFILE} $FLANNEL_OPTIONS & child=$! while test \! -e /run/flannel/subnet.env @@ -17,4 +19,6 @@ done /usr/libexec/flannel/mk-docker-opts.sh -k DOCKER_NETWORK_OPTIONS -d /run/flannel/docker +systemd-notify --ready + wait $child diff --git a/service.template b/service.template index d25dc8c..b6a2883 100644 --- a/service.template +++ b/service.template @@ -7,9 +7,10 @@ After=$AFTER Before=docker.service [Service] +Type=notify +NotifyAccess=all ExecStart=$EXEC_START ExecStop=$EXEC_STOP -ExecStartPost=/usr/bin/sh -c "while test \! -s ${RUN_DIRECTORY}/${NAME}/docker; do sleep 0.1; done" ExecStopPost=/bin/rm /etc/systemd/system/docker.service.d/$NAME.conf Restart=on-failure WorkingDirectory=$DESTDIR From 3cede381826cc3a2447b0f58dc9a97015d12be04 Mon Sep 17 00:00:00 2001 From: Clement Verna Date: Mon, 20 Aug 2018 19:31:12 +0200 Subject: [PATCH 3/3] Drop Release label in favor of OSBS release_bump plugin. OSBS can automatically bump the release number, for that we just need to drop the label from the Dockerfile See https://pagure.io/ContainerSIG/container-sig/issue/1 Signed-off-by: Clement Verna --- Dockerfile | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index be9ee85..b36dd50 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,11 +2,10 @@ FROM registry.fedoraproject.org/fedora:rawhide ENV container=docker FLANNELD_ETCD_ENDPOINTS="http://127.0.0.1:2379" FLANNELD_ETCD_PREFIX="/atomic.io/network" -ENV VERSION=0 RELEASE=8 ARCH=x86_64 +ENV VERSION=0 ARCH=x86_64 LABEL com.redhat.component="flannel" \ name="$FGC/flannel" \ version="$VERSION" \ - release="$RELEASE.$DISTTAG" \ architecture="$ARCH" \ summary="An etcd driven address agent, intended to be run as a system container" \ maintainer="Giuseppe Scrivano " \