POC no setuid, setgid caps
Signed-off-by: Jess Frazelle <jess@mesosphere.com>
This commit is contained in:
parent
69cba73cf6
commit
2b527491fe
10 changed files with 156 additions and 171 deletions
2
Makefile
2
Makefile
|
@ -40,7 +40,7 @@ static: $(BINDIR) rootfs.go
|
|||
@echo "+ $@"
|
||||
CGO_ENABLED=1 go build -tags "$(BUILDTAGS) cgo static_build" \
|
||||
-ldflags "-w -extldflags -static ${LDFLAGS}" -o bin/$(notdir $(IMAGE)) .
|
||||
@sudo setcap cap_chown,cap_fowner,cap_dac_override,cap_setuid,cap_setgid+ep ./bin/$(notdir $(IMAGE))
|
||||
@sudo setcap cap_chown,cap_fowner,cap_dac_override+ep ./bin/$(notdir $(IMAGE))
|
||||
@echo "Static container created at: ./bin/$(notdir $(IMAGE))"
|
||||
@echo "Run with ./bin/$(notdir $(IMAGE))"
|
||||
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue