Tuesday, 2019-03-12

kata-irc-bot<xwlpt> Hi @graham.whaley @eric.ernst Just want to know that: Is container runs in privileged mode is still a limitation for Kata. `https://github.com/kata-containers/documentation/blob/master/Limitations.md#docker-run---privileged`01:16
kata-irc-bot<archana.m.shinde> @xwlpt That needs to be updated01:51
kata-irc-bot<archana.m.shinde> We do support `privileged` flag, but the privileges are applied to the guest rather than the host01:52
kata-irc-bot<archana.m.shinde> you get all `capabilities` within the guest, access to all devices within the guest01:53
kata-irc-bot<archana.m.shinde> in that sense it is different from the true notion of privileged in case of runc01:53
kata-irc-bot<xwlpt> Thanks @archana.m.shinde Do you know at which version is it supported?01:54
kata-irc-bot<archana.m.shinde> we also cannot make any changes to the host networking01:54
kata-irc-bot<archana.m.shinde> @xwlpt I dont really recall, will have to check01:55
kata-irc-bot<archana.m.shinde> what version are you using?01:56
kata-irc-bot<xwlpt> I am using kata 1.5 now. But have not tried it.01:57
kata-irc-bot<archana.m.shinde> you should have it then01:57
kata-irc-bot<archana.m.shinde> I think it was added atleast a couple of versions back01:57
kata-irc-bot<xwlpt> Another question is: Do you know why we have `PrivateDevices=yes ` in this serivce configuration?  `https://github.com/kata-containers/documentation/blob/master/Developer-Guide.md#create-a-debug-systemd-service` I want to remove it, but not have any context for why it is added? Is there any reason for we need to enable it?  cc @graham.whaley @eric.ernst01:58
kata-irc-bot<xwlpt> @archana.m.shinde I will have a try.01:58
kata-irc-bot<xwlpt> Since kata support privileged containers now as @archana.m.shinde  Another issue is how to limit user  just can run privileged containers for runv but not runc.  As I know, there is no RBAC based on runtimeClass in k8s. Does anyone have ideas for this?  @graham.whaley @eric.ernst @xu @archana.m.shinde02:11
*** openstack has joined #kata-dev02:22
*** ChanServ sets mode: +o openstack02:22
kata-irc-bot<krsna1729> @xwlpt see if admission controllers concept is useful02:47
*** stefanha has quit IRC06:07
*** irclogbot_0 has quit IRC06:09
*** irclogbot_0 has joined #kata-dev06:09
*** stefanha has joined #kata-dev07:35
*** sgarzare has joined #kata-dev08:16
*** sameo has joined #kata-dev08:21
*** tmhoang has joined #kata-dev08:32
*** jodh has joined #kata-dev08:41
*** gwhaley has joined #kata-dev08:53
kata-irc-bot<thierry> Kubecon EU CFP results are in...08:55
kata-irc-bot<thierry> My talk about demistifying the container runtimes landscape (where I planned to show complementarity between kata and Firecracker amongst other things) was rejected08:56
kata-irc-bot<thierry> How did others fare?08:57
stefanhathierry: "your submission, virtio-fs: container storage for lightweight virtual machines, has been added to our waitlist" ¯\_(ツ)_/¯09:11
*** lpetrut has joined #kata-dev10:33
kata-irc-bot<xu> not accepted11:42
*** gwhaley has quit IRC12:06
*** gwhaley has joined #kata-dev12:59
*** fuentess has joined #kata-dev13:18
*** devimc has joined #kata-dev13:21
*** sgarzare has quit IRC13:25
*** sgarzare has joined #kata-dev13:28
kata-irc-bot<raravena80> waitlisted too ¯\_(ツ)_/¯ .  I think they have a lot of sponsored talks.13:41
stefanhaThe talks 2019 etherpad was here: https://etherpad.openstack.org/p/KataTalks201913:42
* stefanha updates13:43
*** openstack has joined #kata-dev15:37
*** ChanServ sets mode: +o openstack15:37
*** jodh has quit IRC16:03
*** eernst has joined #kata-dev16:13
*** devimc has quit IRC16:48
*** igordc has quit IRC16:48
*** devimc has joined #kata-dev16:49
*** sameo has quit IRC16:49
*** igordc has joined #kata-dev16:52
*** igordc has quit IRC16:53
kata-irc-bot<jose.carlos.venegas.m> @mvedovati same here, we should  remove that commit hash from the packages16:55
*** igordc has joined #kata-dev16:56
kata-irc-bot<jose.carlos.venegas.m> that and have  `=` dependencies  instead of `>=`  to the kata repositories.16:56
kata-irc-bot<mvedovati> correct16:58
*** igordc has quit IRC17:10
*** eernst has quit IRC17:13
*** igordc has joined #kata-dev17:21
*** eernst has joined #kata-dev17:32
*** sgarzare has quit IRC17:34
*** igordc has quit IRC17:43
*** igordc has joined #kata-dev17:48
*** tmhoang has quit IRC17:58
*** gwhaley has quit IRC19:27
*** igordc has quit IRC19:32
*** igordc has joined #kata-dev19:33
*** igordc has quit IRC20:13
*** igordc has joined #kata-dev21:26
*** igordc has quit IRC21:26
*** igordc has joined #kata-dev21:27
*** igordc has quit IRC22:25
*** fuentess has quit IRC22:29
*** devimc has quit IRC22:32
*** igordc has joined #kata-dev22:43

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!