forked from kubevirt/kubevirt
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
virt-launcher: add opt-in feature gate for docker bug workaround
A bug in docker (moby/moby#41370) forces us to implement a workaround in the SELinux options of virt-launcher. This workaround (disabling categories on non-compute containers) weakens the security of the project for all when it is only needed for a very specific use-case: deployments on clusters that have docker nodes with SELinux enforced on the system and enabled in the docker configuration (it is disabled by default). That bug was filed more than 2 years ago, so it is time to disable the workaround by default, with a feature gate for those who need it. Signed-off-by: Jed Lejosne <[email protected]>
- Loading branch information
1 parent
6064090
commit 5f89682
Showing
3 changed files
with
41 additions
and
9 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters