Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[v0.13] allow network.host daemon entitlement by default in container drivers #2255

Closed
tonistiigi opened this issue Feb 12, 2024 · 2 comments · Fixed by #2266
Closed

[v0.13] allow network.host daemon entitlement by default in container drivers #2255

tonistiigi opened this issue Feb 12, 2024 · 2 comments · Fixed by #2266
Assignees
Labels
kind/enhancement New feature or request status/triage
Milestone

Comments

@tonistiigi
Copy link
Member

Description

Based on comments in moby/buildkit#4524 (comment) , there shouldn't be a need to set --allowed-entitlemtns network.host as buildkitd flags when builder runs in a container as the container network is already isolated. At least when --driver-opt network does not equal host.

@crazy-max
Copy link
Member

I think it would also makes sense for kubernetes driver (cc @AkihiroSuda)

@crazy-max
Copy link
Member

I was wondering one thing. Should we set this entitlement silently when creating the builder or set it in buildx store? I think silently makes sense.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/enhancement New feature or request status/triage
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants