Skip to content

Commit

Permalink
Fix documentation on --security-opt seccomp
Browse files Browse the repository at this point in the history
Missing documentation and man pages on seccomp options.
Signed-off-by: Dan Walsh <[email protected]>
  • Loading branch information
rhatdan committed Mar 17, 2016
1 parent 8bbe3de commit 450fa75
Show file tree
Hide file tree
Showing 3 changed files with 15 additions and 0 deletions.
3 changes: 3 additions & 0 deletions docs/reference/run.md
Original file line number Diff line number Diff line change
Expand Up @@ -608,6 +608,9 @@ with the same logic -- if the original volume was specified with a name it will
to the container
--security-opt="no-new-privileges" : Disable container processes from gaining
new privileges
--security-opt="seccomp:unconfined": Turn off seccomp confinement for the container
--security-opt="seccomp:profile.json: White listed syscalls seccomp Json file to be used as a seccomp filter


You can override the default labeling scheme for each container by specifying
the `--security-opt` flag. For example, you can specify the MCS/MLS level, a
Expand Down
9 changes: 9 additions & 0 deletions man/docker-create.1.md
Original file line number Diff line number Diff line change
Expand Up @@ -316,6 +316,15 @@ unit, `b` is used. Set LIMIT to `-1` to enable unlimited swap.
**--security-opt**=[]
Security Options

"label:user:USER" : Set the label user for the container
"label:role:ROLE" : Set the label role for the container
"label:type:TYPE" : Set the label type for the container
"label:level:LEVEL" : Set the label level for the container
"label:disable" : Turn off label confinement for the container
"no-new-privileges" : Disable container processes from gaining additional privileges
"seccomp:unconfined" : Turn off seccomp confinement for the container
"seccomp:profile.json : White listed syscalls seccomp Json file to be used as a seccomp filter

**--stop-signal**=*SIGTERM*
Signal to stop a container. Default is SIGTERM.

Expand Down
3 changes: 3 additions & 0 deletions man/docker-run.1.md
Original file line number Diff line number Diff line change
Expand Up @@ -468,8 +468,11 @@ its root filesystem mounted as read only prohibiting any writes.
"label:type:TYPE" : Set the label type for the container
"label:level:LEVEL" : Set the label level for the container
"label:disable" : Turn off label confinement for the container

"no-new-privileges" : Disable container processes from gaining additional privileges

"seccomp:unconfined" : Turn off seccomp confinement for the container
"seccomp:profile.json : White listed syscalls seccomp Json file to be used as a seccomp filter

**--stop-signal**=*SIGTERM*
Signal to stop a container. Default is SIGTERM.
Expand Down

0 comments on commit 450fa75

Please sign in to comment.