A container may log to the journal (hq ADR 0179)
A jail reads a log; a container's output went to a file of the runtime's own under a path that changes on recreate, so no jail could read a container's service. logging: journald runs the container with the journal as its driver, named in the spec so moving it recreates it; any other place is refused.
This commit is contained in:
@@ -952,6 +952,14 @@ type Container struct {
|
||||
// container; a privileged container stays undeclarable.
|
||||
Capabilities []string `json:"capabilities,omitempty"`
|
||||
|
||||
// Logging names where the runtime sends this container's output: "journald" sends it to the
|
||||
// machine's journal, under the container's name, where what reads the machine's logs — its
|
||||
// intrusion prevention first of all (novox/hq ADR 0179) — can read it the way it reads the
|
||||
// machine's own services. Empty keeps the runtime's default, which is a file of the runtime's
|
||||
// own that nothing but the runtime reads. Part of the spec: a container that logs elsewhere
|
||||
// is a different container, and the runtime cannot change a running one's driver.
|
||||
Logging string `json:"logging,omitempty"`
|
||||
|
||||
// Networks are networks this container also joins once created, by name — a found network a
|
||||
// per-machine setting keeps for a taken container (novox/hq ADR 0163, rule 4), so a
|
||||
// neighbour that resolves it there keeps resolving it until the neighbour is taken too.
|
||||
@@ -1057,6 +1065,10 @@ func (c *Container) validate(where string, _ bool) []string {
|
||||
"capability's name (CAP_NET_ADMIN or NET_ADMIN)")
|
||||
}
|
||||
}
|
||||
if c.Logging != "" && c.Logging != "journald" {
|
||||
problems = append(problems, where+": logging is "+strconv.Quote(c.Logging)+", and the only place a "+
|
||||
"container's output can be sent besides the runtime's own file is \"journald\"")
|
||||
}
|
||||
for _, n := range c.Networks {
|
||||
problems = append(problems, (&Network{Name: n}).validate(where+": networks", false)...)
|
||||
if n == c.Network {
|
||||
|
||||
Reference in New Issue
Block a user