[ https://issues.apache.org/jira/browse/YARN-7904?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16734534#comment-16734534 ]
Eric Badger commented on YARN-7904: ----------------------------------- bq. Instead of making all bind-mounted directories read-only. We may want to consider to block privileged container from non-entrypoint mode to reduce the incompatible changes to the minimum. Thought? This makes sense to me, but only because I don't see an easy solution for how to deal with user logs or user data written as root. So I'm +1 for this idea. > Privileged, trusted containers need all of their bind-mounted directories to > be read-only > ----------------------------------------------------------------------------------------- > > Key: YARN-7904 > URL: https://issues.apache.org/jira/browse/YARN-7904 > Project: Hadoop YARN > Issue Type: Sub-task > Reporter: Eric Badger > Assignee: Zhaohui Xin > Priority: Major > Labels: Docker > > Since they will be running as some other user than themselves, the NM likely > won't be able to clean up after them because of permissions issues. So, to > prevent this, we should make these directories read-only. -- This message was sent by Atlassian JIRA (v7.6.3#76005) --------------------------------------------------------------------- To unsubscribe, e-mail: yarn-issues-unsubscr...@hadoop.apache.org For additional commands, e-mail: yarn-issues-h...@hadoop.apache.org