[ 
https://issues.apache.org/jira/browse/YARN-7960?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16484405#comment-16484405
 ] 

Hudson commented on YARN-7960:
------------------------------

FAILURE: Integrated in Jenkins build Hadoop-trunk-Commit #14252 (See 
[https://builds.apache.org/job/Hadoop-trunk-Commit/14252/])
YARN-7960.  Added security flag no-new-privileges for YARN Docker (eyang: rev 
6176d2b35c85715aae93526236c29540f71ecac8)
* (edit) 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-site/src/site/markdown/DockerContainers.md
* (edit) 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/test/utils/test_docker_util.cc
* (edit) hadoop-yarn-project/hadoop-yarn/conf/container-executor.cfg
* (edit) 
hadoop-yarn-project/hadoop-yarn/hadoop-yarn-server/hadoop-yarn-server-nodemanager/src/main/native/container-executor/impl/utils/docker-util.c


> Add no-new-privileges flag to docker run
> ----------------------------------------
>
>                 Key: YARN-7960
>                 URL: https://issues.apache.org/jira/browse/YARN-7960
>             Project: Hadoop YARN
>          Issue Type: Sub-task
>            Reporter: Eric Badger
>            Assignee: Eric Badger
>            Priority: Major
>              Labels: Docker
>             Fix For: 3.2.0, 3.1.1
>
>         Attachments: YARN-7960.001.patch, YARN-7960.002.patch
>
>
> Minimally, this should be used for unprivileged containers. It's a cheap way 
> to add an extra layer of security to the docker model. For privileged 
> containers, it might be appropriate to omit this flag
> https://github.com/moby/moby/pull/20727



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: yarn-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: yarn-issues-h...@hadoop.apache.org

Reply via email to