Thursday, 2018-09-13

*** zerocoolback has joined #kata-dev00:04
*** zerocoolback has quit IRC00:09
*** sameo has quit IRC00:13
*** jugs has quit IRC01:11
*** jugs has joined #kata-dev01:12
*** dklyle has joined #kata-dev01:19
*** dklyle has quit IRC01:39
*** mcastelino__ has joined #kata-dev01:44
*** mcastelino_ has quit IRC01:47
*** mcastelino__ has quit IRC01:56
*** fuentess has quit IRC02:31
*** zerocoolback has joined #kata-dev03:09
kata-irc-bot<raravena80> I suppose we already have this: https://github.com/kata-containers/documentation/blob/master/architecture.md for arch. I'll take a look at maybe adding something with a noob contributor angle.03:38
*** sjas has joined #kata-dev04:20
*** sjas_ has quit IRC04:23
*** zerocoolback has quit IRC06:20
*** jodh has joined #kata-dev06:38
*** jodh has quit IRC06:38
*** jodh has joined #kata-dev06:38
*** davidgiluk has joined #kata-dev07:59
*** gwhaley has joined #kata-dev08:01
*** sameo has joined #kata-dev08:17
*** changcheng has quit IRC09:05
*** libregeekingkid has joined #kata-dev09:39
*** changcheng has joined #kata-dev09:48
*** zerocoolback has joined #kata-dev10:51
*** zerocoolback has joined #kata-dev10:52
*** libregeekingkid has quit IRC11:39
*** devimc has joined #kata-dev11:53
*** eernst has joined #kata-dev11:56
xzrhmm, I don't suppose there's any kind of a timeline for implementing --security-opt="label" ?12:06
gwhaleyhi xzr: I'm not sure that's been discussed - is there an open github Issue for it? Worth rasing if not, and asking for input....12:16
gwhaleyof course, PRs also most welcome ;-)12:16
xzrwell, out of theoretical interest, where does the implementation for handling those parameters happen?12:23
gwhaleyxzr: hmm, a look in the docker docs didn't give me much info on what those 'label' items actually do https://docs.docker.com/engine/reference/run/#security-configuration12:40
gwhaleyso, I suspect it will be either the runtime (if this is a host side thing or something that needs to get passed into the container in the json), or an agent thing (if this is something that needs setting up inside the container/VM)12:41
gwhaleyI reckon @devimc will have a better idea maybe ?12:42
kata-irc-bot<james.o.hunt> https://github.com/kata-containers/kata-containers/issues/31@atte.pellikka -12:49
kata-irc-bot<james.o.hunt> err paste fail there ;)12:49
xzrI suspect it triggers the labeling for selinux context12:55
gwhaleyxzr: and I think we'll be running selinux inside the VM, in which case I think we'd need to pass this in to the agent so it can set the context on, err, the container namespace?12:58
gwhaleya possible route to chase then is to see how this happens in runc - if it passes the info into libcontainer - and if so, that is also what we'd do inside the agent (which sits on libcontainer)13:00
xzrnot quite sure how it all ties together, I'll try and dig more13:07
*** eernst has quit IRC13:36
*** fuentess has joined #kata-dev14:03
*** annabelleB has joined #kata-dev14:11
*** annabelleB has quit IRC14:15
*** annabelleB has joined #kata-dev14:18
*** eernst has joined #kata-dev14:44
*** annabelleB has quit IRC14:52
*** annabelleB has joined #kata-dev15:01
*** dklyle has joined #kata-dev15:11
*** sameo has quit IRC15:21
*** sameo has joined #kata-dev15:34
*** jodh has quit IRC15:49
*** sameo has quit IRC15:53
*** marcov__ is now known as marcov16:02
*** mcastelino has joined #kata-dev16:04
*** eernst has quit IRC16:35
*** gwhaley has quit IRC16:58
*** fuentess1 has joined #kata-dev17:40
*** fuentess has quit IRC17:40
*** LinuxMe has joined #kata-dev17:54
*** LinuxMe has quit IRC18:02
*** sameo has joined #kata-dev18:07
*** eernst has joined #kata-dev18:12
*** zerocoolback has quit IRC18:47
*** simosx has joined #kata-dev18:53
*** annabelleB has quit IRC18:55
*** simosx has quit IRC18:56
*** annabelleB has joined #kata-dev19:10
*** annabelleB has quit IRC19:11
*** davidgiluk has quit IRC19:29
*** eernst has quit IRC19:55
*** annabelleB has joined #kata-dev20:00
*** mcastelino_ has joined #kata-dev21:02
*** mcastelino has quit IRC21:05
*** mcastelino_ has quit IRC21:06
*** fuentess1 has quit IRC21:16
*** devimc has quit IRC21:16
*** annabelleB has quit IRC21:22
*** annabelleB has joined #kata-dev21:22
*** annabelleB has quit IRC21:34
*** annabelleB has joined #kata-dev21:39
*** annabelleB has quit IRC22:07
*** annabelleB has joined #kata-dev22:10
*** annabelleB has quit IRC22:49
*** annabelleB has joined #kata-dev22:52
*** annabelleB has quit IRC23:08
*** annabelleB has joined #kata-dev23:25
*** annabelleB has quit IRC23:49
*** annabelleB has joined #kata-dev23:59

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!