Add cgroup mount in the recommended config
And allow cgroup mount take flags from user configs. As we show ro in the recommendation, so hard-coded read-only flag should be removed. Signed-off-by: Qiang Huang <h.huangqiang@huawei.com>
This commit is contained in:
parent
31f23e4429
commit
d7181a73e4
|
@ -111,6 +111,12 @@ user named `daemon` defined within that file-system.
|
|||
"source": "sysfs",
|
||||
"destination": "/sys",
|
||||
"options": "nosuid,noexec,nodev"
|
||||
},
|
||||
{
|
||||
"type": "cgroup",
|
||||
"source": "cgroup",
|
||||
"destination": "/sys/fs/cgroup",
|
||||
"options": "nosuid,noexec,nodev,relatime,ro"
|
||||
}
|
||||
],
|
||||
"linux": {
|
||||
|
|
|
@ -184,7 +184,7 @@ func mountToRootfs(m *configs.Mount, rootfs, mountLabel string) error {
|
|||
Device: "bind",
|
||||
Source: filepath.Join(mm.Mountpoint, dir),
|
||||
Destination: filepath.Join(m.Destination, strings.Join(mm.Subsystems, ",")),
|
||||
Flags: syscall.MS_BIND | syscall.MS_REC | syscall.MS_RDONLY,
|
||||
Flags: syscall.MS_BIND | syscall.MS_REC | m.Flags,
|
||||
})
|
||||
}
|
||||
tmpfs := &configs.Mount{
|
||||
|
|
Loading…
Reference in New Issue