A container may log to the journal (hq ADR 0179) #73

Merged
mesh-admin merged 1 commits from feat/the-intrusion-seat-serves-its-verbs into main 2026-10-02 15:04:02 +00:00
Contributor

logging: journald on a container runs it with the journal as its log driver and names the place in the spec, so moving it recreates the container; any place other than the journal is refused. This is what lets a jail read a container's service by its name (hq ADR 0179, to-be 31). Rolls first: an older host refuses a declaration carrying the field.

Tests: declaration parse/refuse, run arguments and spec in internal/apply/logging_test.go.

`logging: journald` on a container runs it with the journal as its log driver and names the place in the spec, so moving it recreates the container; any place other than the journal is refused. This is what lets a jail read a container's service by its name (hq ADR 0179, to-be 31). Rolls first: an older host refuses a declaration carrying the field. Tests: declaration parse/refuse, run arguments and spec in `internal/apply/logging_test.go`.
mesh-admin added 1 commit 2026-10-02 15:03:20 +00:00
A jail reads a log; a container's output went to a file of the runtime's own under a path that
changes on recreate, so no jail could read a container's service. logging: journald runs the
container with the journal as its driver, named in the spec so moving it recreates it; any other
place is refused.
mesh-admin merged commit ca7c4a5915 into main 2026-10-02 15:04:02 +00:00
mesh-admin deleted branch feat/the-intrusion-seat-serves-its-verbs 2026-10-02 15:04:02 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-host#73