Re: [openstack-dev] [Zun] Containers in privileged mode

2018-01-03 Thread Hongbin Lu
On Wed, Jan 3, 2018 at 10:41 AM, João Paulo Sá da Silva < joao-sa-si...@alticelabs.com> wrote: > Hello, > > > > I created the BP: https://blueprints.launchpad. > net/zun/+spec/add-capacities-to-containers . > Thanks for creating the BP. > > > About the clear containers, I’m not quite sure how

Re: [openstack-dev] [Zun] Containers in privileged mode

2018-01-03 Thread João Paulo Sá da Silva
Hello, I created the BP: https://blueprints.launchpad.net/zun/+spec/add-capacities-to-containers . About the clear containers, I'm not quite sure how using them solves my capabilities situation. Can you elaborate on that? Will zun ever be able to launch LXD containers? Kind regards, João

Re: [openstack-dev] [Zun] Containers in privileged mode

2018-01-02 Thread Hongbin Lu
Please find my reply inline. Best regards, Hongbin On Tue, Jan 2, 2018 at 2:06 PM, João Paulo Sá da Silva < joao-sa-si...@alticelabs.com> wrote: > Thanks for your answer, Hongbin, it is very appreciated. > > > > The use case is to use Virtualized Network Functions in containers instead > of

[openstack-dev] [Zun] Containers in privileged mode

2018-01-02 Thread João Paulo Sá da Silva
Thanks for your answer, Hongbin, it is very appreciated. The use case is to use Virtualized Network Functions in containers instead of virtual machines. The rational for using containers instead of VMs is better VNF density in resource constrained hosts. The goal is to have several VNFs (DHCP,

Re: [openstack-dev] [Zun] Containers in privileged mode

2018-01-02 Thread Hongbin Lu
Hi Joao, Right now, it is impossible to create containers with escalated privileged, such as setting privileged mode or adding additional caps. This is intentional for security reasons. Basically, what Zun currently provides is "serverless" containers, which means Zun is not using VMs to isolate

[openstack-dev] [Zun] Containers in privileged mode

2018-01-02 Thread João Paulo Sá da Silva
Hello! Is it possible to create containers in privileged mode or to add caps as NET_ADMIN? Kind regards, João __ OpenStack Development Mailing List (not for usage questions) Unsubscribe: