[ 
https://issues.apache.org/jira/browse/YARN-7904?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16734534#comment-16734534
 ] 

Eric Badger commented on YARN-7904:
-----------------------------------

bq. Instead of making all bind-mounted directories read-only. We may want to 
consider to block privileged container from non-entrypoint mode to reduce the 
incompatible changes to the minimum. Thought?
This makes sense to me, but only because I don't see an easy solution for how 
to deal with user logs or user data written as root. So I'm +1 for this idea. 

> Privileged, trusted containers need all of their bind-mounted directories to 
> be read-only
> -----------------------------------------------------------------------------------------
>
>                 Key: YARN-7904
>                 URL: https://issues.apache.org/jira/browse/YARN-7904
>             Project: Hadoop YARN
>          Issue Type: Sub-task
>            Reporter: Eric Badger
>            Assignee: Zhaohui Xin
>            Priority: Major
>              Labels: Docker
>
> Since they will be running as some other user than themselves, the NM likely 
> won't be able to clean up after them because of permissions issues. So, to 
> prevent this, we should make these directories read-only.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: yarn-issues-unsubscr...@hadoop.apache.org
For additional commands, e-mail: yarn-issues-h...@hadoop.apache.org

Reply via email to