A container may log to the journal (hq ADR 0179)
A jail reads a log; a container's output went to a file of the runtime's own under a path that changes on recreate, so no jail could read a container's service. logging: journald runs the container with the journal as its driver, named in the spec so moving it recreates it; any other place is refused.
This commit is contained in:
@@ -1607,6 +1607,10 @@ func containerSpecReading(r *declaration.Container, declares, reads map[string]s
|
||||
for _, c := range r.Capabilities {
|
||||
b.WriteString("cap " + c + "\n")
|
||||
}
|
||||
// And where it logs (ADR 0179): the runtime cannot move a running container's output.
|
||||
if r.Logging != "" {
|
||||
b.WriteString("log " + r.Logging + "\n")
|
||||
}
|
||||
// The cadence is part of what was declared, so a changed schedule is a changed spec — the marker
|
||||
// moves and the install is reported "updated" and re-established. Added only when present, so no
|
||||
// ordinary container's or run-once step's digest moves for a field it does not set.
|
||||
@@ -1804,6 +1808,11 @@ func applyContainer(ctx context.Context, r *declaration.Container, run Runner,
|
||||
for _, c := range r.Capabilities {
|
||||
args = append(args, "--cap-add", c)
|
||||
}
|
||||
if r.Logging != "" {
|
||||
// The journal keeps the container's name on every line (CONTAINER_NAME), which is what a
|
||||
// jail matches on (novox/hq ADR 0179); `docker logs` keeps working against the journal.
|
||||
args = append(args, "--log-driver", r.Logging)
|
||||
}
|
||||
for _, d := range r.Dns {
|
||||
args = append(args, "--dns", d)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user