Skip to content

Conversation

@crazy-max
Copy link
Member

fixes #2255

@AkihiroSuda
Copy link
Collaborator

This seems to be a potentially breaking change (from security perspective), and has to be documented?


if !hasNetworkHostEntitlement {
// always set network.host entitlement as container network is
// isolated for docker-container and kubernetes drivers
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In the comment could you explain the purpose of setting the entitlement by default?

@tonistiigi
Copy link
Member

This seems to be a potentially breaking change (from security perspective),

It is not. The default networking for build step containers if builder was in container was already host (meaning host inside the container, not host of machine) and will remain like this in v0.13. This was without setting any --network=host.

@crazy-max crazy-max force-pushed the container-driver-host-entl branch from ae3436e to 48ab88d Compare February 23, 2024 10:14
@crazy-max crazy-max requested a review from tonistiigi February 23, 2024 10:15
@crazy-max crazy-max force-pushed the container-driver-host-entl branch 3 times, most recently from 2d6ae5c to 4d88ca6 Compare February 23, 2024 10:56
Signed-off-by: CrazyMax <1951866+crazy-max@users.noreply.github.com>
@crazy-max crazy-max force-pushed the container-driver-host-entl branch from 4d88ca6 to e008b84 Compare February 23, 2024 21:23
@crazy-max crazy-max merged commit d891634 into docker:master Feb 23, 2024
@crazy-max crazy-max deleted the container-driver-host-entl branch February 23, 2024 21:41
@crazy-max crazy-max added this to the v0.13.0 milestone Sep 11, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v0.13] allow network.host daemon entitlement by default in container drivers

3 participants