*** zerocoolback has joined #kata-dev | 00:04 | |
*** zerocoolback has quit IRC | 00:09 | |
*** sameo has quit IRC | 00:13 | |
*** jugs has quit IRC | 01:11 | |
*** jugs has joined #kata-dev | 01:12 | |
*** dklyle has joined #kata-dev | 01:19 | |
*** dklyle has quit IRC | 01:39 | |
*** mcastelino__ has joined #kata-dev | 01:44 | |
*** mcastelino_ has quit IRC | 01:47 | |
*** mcastelino__ has quit IRC | 01:56 | |
*** fuentess has quit IRC | 02:31 | |
*** zerocoolback has joined #kata-dev | 03:09 | |
kata-irc-bot | <raravena80> I suppose we already have this: https://github.com/kata-containers/documentation/blob/master/architecture.md for arch. I'll take a look at maybe adding something with a noob contributor angle. | 03:38 |
---|---|---|
*** sjas has joined #kata-dev | 04:20 | |
*** sjas_ has quit IRC | 04:23 | |
*** zerocoolback has quit IRC | 06:20 | |
*** jodh has joined #kata-dev | 06:38 | |
*** jodh has quit IRC | 06:38 | |
*** jodh has joined #kata-dev | 06:38 | |
*** davidgiluk has joined #kata-dev | 07:59 | |
*** gwhaley has joined #kata-dev | 08:01 | |
*** sameo has joined #kata-dev | 08:17 | |
*** changcheng has quit IRC | 09:05 | |
*** libregeekingkid has joined #kata-dev | 09:39 | |
*** changcheng has joined #kata-dev | 09:48 | |
*** zerocoolback has joined #kata-dev | 10:51 | |
*** zerocoolback has joined #kata-dev | 10:52 | |
*** libregeekingkid has quit IRC | 11:39 | |
*** devimc has joined #kata-dev | 11:53 | |
*** eernst has joined #kata-dev | 11:56 | |
xzr | hmm, I don't suppose there's any kind of a timeline for implementing --security-opt="label" ? | 12:06 |
gwhaley | hi xzr: I'm not sure that's been discussed - is there an open github Issue for it? Worth rasing if not, and asking for input.... | 12:16 |
gwhaley | of course, PRs also most welcome ;-) | 12:16 |
xzr | well, out of theoretical interest, where does the implementation for handling those parameters happen? | 12:23 |
gwhaley | xzr: hmm, a look in the docker docs didn't give me much info on what those 'label' items actually do https://docs.docker.com/engine/reference/run/#security-configuration | 12:40 |
gwhaley | so, I suspect it will be either the runtime (if this is a host side thing or something that needs to get passed into the container in the json), or an agent thing (if this is something that needs setting up inside the container/VM) | 12:41 |
gwhaley | I reckon @devimc will have a better idea maybe ? | 12:42 |
kata-irc-bot | <james.o.hunt> https://github.com/kata-containers/kata-containers/issues/31@atte.pellikka - | 12:49 |
kata-irc-bot | <james.o.hunt> err paste fail there ;) | 12:49 |
xzr | I suspect it triggers the labeling for selinux context | 12:55 |
gwhaley | xzr: and I think we'll be running selinux inside the VM, in which case I think we'd need to pass this in to the agent so it can set the context on, err, the container namespace? | 12:58 |
gwhaley | a possible route to chase then is to see how this happens in runc - if it passes the info into libcontainer - and if so, that is also what we'd do inside the agent (which sits on libcontainer) | 13:00 |
xzr | not quite sure how it all ties together, I'll try and dig more | 13:07 |
*** eernst has quit IRC | 13:36 | |
*** fuentess has joined #kata-dev | 14:03 | |
*** annabelleB has joined #kata-dev | 14:11 | |
*** annabelleB has quit IRC | 14:15 | |
*** annabelleB has joined #kata-dev | 14:18 | |
*** eernst has joined #kata-dev | 14:44 | |
*** annabelleB has quit IRC | 14:52 | |
*** annabelleB has joined #kata-dev | 15:01 | |
*** dklyle has joined #kata-dev | 15:11 | |
*** sameo has quit IRC | 15:21 | |
*** sameo has joined #kata-dev | 15:34 | |
*** jodh has quit IRC | 15:49 | |
*** sameo has quit IRC | 15:53 | |
*** marcov__ is now known as marcov | 16:02 | |
*** mcastelino has joined #kata-dev | 16:04 | |
*** eernst has quit IRC | 16:35 | |
*** gwhaley has quit IRC | 16:58 | |
*** fuentess1 has joined #kata-dev | 17:40 | |
*** fuentess has quit IRC | 17:40 | |
*** LinuxMe has joined #kata-dev | 17:54 | |
*** LinuxMe has quit IRC | 18:02 | |
*** sameo has joined #kata-dev | 18:07 | |
*** eernst has joined #kata-dev | 18:12 | |
*** zerocoolback has quit IRC | 18:47 | |
*** simosx has joined #kata-dev | 18:53 | |
*** annabelleB has quit IRC | 18:55 | |
*** simosx has quit IRC | 18:56 | |
*** annabelleB has joined #kata-dev | 19:10 | |
*** annabelleB has quit IRC | 19:11 | |
*** davidgiluk has quit IRC | 19:29 | |
*** eernst has quit IRC | 19:55 | |
*** annabelleB has joined #kata-dev | 20:00 | |
*** mcastelino_ has joined #kata-dev | 21:02 | |
*** mcastelino has quit IRC | 21:05 | |
*** mcastelino_ has quit IRC | 21:06 | |
*** fuentess1 has quit IRC | 21:16 | |
*** devimc has quit IRC | 21:16 | |
*** annabelleB has quit IRC | 21:22 | |
*** annabelleB has joined #kata-dev | 21:22 | |
*** annabelleB has quit IRC | 21:34 | |
*** annabelleB has joined #kata-dev | 21:39 | |
*** annabelleB has quit IRC | 22:07 | |
*** annabelleB has joined #kata-dev | 22:10 | |
*** annabelleB has quit IRC | 22:49 | |
*** annabelleB has joined #kata-dev | 22:52 | |
*** annabelleB has quit IRC | 23:08 | |
*** annabelleB has joined #kata-dev | 23:25 | |
*** annabelleB has quit IRC | 23:49 | |
*** annabelleB has joined #kata-dev | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!