You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently running a privileged container allows to modify values in /proc/sys file system. As it turns out runC prohibits it and, finally, if docker completely moves to runC some deployments will break.
Can /proc/sys still be made writable?
The text was updated successfully, but these errors were encountered:
I'm confused, wasn't this fixed in #716? You can change the ReadonlyPaths list of paths so that it doesn't include /proc/sys. What's left is for Docker (and maybe containerd) to correctly set the OCI config.
Currently running a privileged container allows to modify values in
/proc/sys
file system. As it turns out runC prohibits it and, finally, if docker completely moves to runC some deployments will break.Can
/proc/sys
still be made writable?The text was updated successfully, but these errors were encountered: