You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
which, from a security standpoint, is a really strong no-go. /var/run is mounted writable... there will be more on the host system that is writing to that directory including crucial system services. Then the whole root file system is mounted in read-only. That exposes all data of the host.
Is there no way to run cadvisor in a more restricted way?
The text was updated successfully, but these errors were encountered:
which, from a security standpoint, is a really strong no-go. /var/run is
mounted writable... there will be more on the host system that is writing
to that directory including crucial system services. Then the whole root
file system is mounted in read-only. That exposes all data of the host.
Is there no way to run cadvisor in a more restricted way?
—
Reply to this email directly or view it on GitHub #1069.
I tried cadvisor and the README suggests to do:
which, from a security standpoint, is a really strong no-go.
/var/run
is mounted writable... there will be more on the host system that is writing to that directory including crucial system services. Then the whole root file system is mounted in read-only. That exposes all data of the host.Is there no way to run cadvisor in a more restricted way?
The text was updated successfully, but these errors were encountered: