Skip to content

Commit 03b0cc3

Browse files
authored
Merge pull request #2029 from dashpole/update_security
Update documentation to make /var/run read-only
2 parents eb02a5e + d1b3158 commit 03b0cc3

File tree

2 files changed

+7
-1
lines changed

2 files changed

+7
-1
lines changed

README.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ To quickly tryout cAdvisor on your machine with Docker, we have a Docker image t
1313
```
1414
sudo docker run \
1515
--volume=/:/rootfs:ro \
16-
--volume=/var/run:/var/run:rw \
16+
--volume=/var/run:/var/run:ro \
1717
--volume=/sys:/sys:ro \
1818
--volume=/var/lib/docker/:/var/lib/docker:ro \
1919
--volume=/dev/disk/:/dev/disk:ro \

deploy/kubernetes/base/daemonset.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,9 @@ spec:
3030
- name: docker
3131
mountPath: /var/lib/docker
3232
readOnly: true
33+
- name: disk
34+
mountPath: /dev/disk
35+
readOnly: true
3336
ports:
3437
- name: http
3538
containerPort: 8080
@@ -49,3 +52,6 @@ spec:
4952
- name: docker
5053
hostPath:
5154
path: /var/lib/docker
55+
- name: disk
56+
hostPath:
57+
path: /dev/disk

0 commit comments

Comments
 (0)