Details
-
Task
-
Status: Resolved
-
Critical
-
Resolution: Done
-
None
-
None
-
Mesosphere Sprint 2018-22, Mesosphere Sprint 2018-23
-
13
Description
Containers launched with Unified Containerizer do not include container-specific CGroup FS mounts under /sys/fs/cgroup, which are created by default by Docker (usually readonly for unprivileged containers). Let's honor the same convention for Mesos containers.
For example, this is needed by Uber's automaxprocs patch for Go programs, which amends GOMAXPROCS per CPU quota and requires access to the CPU cgroup subsystem.