Uploaded image for project: 'Mesos'
  1. Mesos
  2. MESOS-7268

CNI isolator should mount network related /etc/* files in readonly mode

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.4.0
    • containerization, network
    • None

    Description

      The CNI isolator bind mounts, even for containers using host networking, several files from /etc, such as resolv.conf. These should be mounted as readonly inside the container to prevent users running inside the container as root from being able to affect the external machine.

      Attachments

        Activity

          People

            swsnider Silas Snider
            swsnider Silas Snider
            Jie Yu Jie Yu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: