Skip to content

Commit e20d878

Browse files
committed
Add linux capabilities for containers.
Next we need start OVS successfully. Signed-off-by: Nobuhiro MIKI <nob@bobuhiro11.net>
1 parent ab07920 commit e20d878

1 file changed

Lines changed: 84 additions & 3 deletions

File tree

docker-compose.yaml

Lines changed: 84 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,34 @@ services:
66
image: bobuhiro11/containerized-devstack-controller
77
tty: true
88
cap_add:
9-
- ALL
9+
- CHOWN
10+
- DAC_OVERRIDE
11+
- DAC_READ_SEARCH
12+
- FOWNER
13+
- FSETID
14+
- IPC_LOCK
15+
- IPC_OWNER
16+
- KILL
17+
- LEASE
18+
- LINUX_IMMUTABLE
19+
- MAC_ADMIN
20+
- MAC_OVERRIDE
21+
- MKNOD
22+
- NET_ADMIN
23+
- NET_BIND_SERVICE
24+
- NET_BROADCAST
25+
- NET_RAW
26+
- SETFCAP
27+
- SETGID
28+
- SETPCAP
29+
- SETUID
30+
- SYS_ADMIN
31+
- SYS_CHROOT
32+
- SYS_NICE
33+
- SYS_PACCT
34+
- SYS_PTRACE
35+
- SYS_RAWIO
36+
- SYS_RESOURCE
1037
tmpfs:
1138
- /tmp
1239
- /run
@@ -29,7 +56,34 @@ services:
2956
image: bobuhiro11/containerized-devstack-compute-1
3057
tty: true
3158
cap_add:
32-
- ALL
59+
- CHOWN
60+
- DAC_OVERRIDE
61+
- DAC_READ_SEARCH
62+
- FOWNER
63+
- FSETID
64+
- IPC_LOCK
65+
- IPC_OWNER
66+
- KILL
67+
- LEASE
68+
- LINUX_IMMUTABLE
69+
- MAC_ADMIN
70+
- MAC_OVERRIDE
71+
- MKNOD
72+
- NET_ADMIN
73+
- NET_BIND_SERVICE
74+
- NET_BROADCAST
75+
- NET_RAW
76+
- SETFCAP
77+
- SETGID
78+
- SETPCAP
79+
- SETUID
80+
- SYS_ADMIN
81+
- SYS_CHROOT
82+
- SYS_NICE
83+
- SYS_PACCT
84+
- SYS_PTRACE
85+
- SYS_RAWIO
86+
- SYS_RESOURCE
3387
tmpfs:
3488
- /tmp
3589
- /run
@@ -52,7 +106,34 @@ services:
52106
image: bobuhiro11/containerized-devstack-compute-2
53107
tty: true
54108
cap_add:
55-
- ALL
109+
- CHOWN
110+
- DAC_OVERRIDE
111+
- DAC_READ_SEARCH
112+
- FOWNER
113+
- FSETID
114+
- IPC_LOCK
115+
- IPC_OWNER
116+
- KILL
117+
- LEASE
118+
- LINUX_IMMUTABLE
119+
- MAC_ADMIN
120+
- MAC_OVERRIDE
121+
- MKNOD
122+
- NET_ADMIN
123+
- NET_BIND_SERVICE
124+
- NET_BROADCAST
125+
- NET_RAW
126+
- SETFCAP
127+
- SETGID
128+
- SETPCAP
129+
- SETUID
130+
- SYS_ADMIN
131+
- SYS_CHROOT
132+
- SYS_NICE
133+
- SYS_PACCT
134+
- SYS_PTRACE
135+
- SYS_RAWIO
136+
- SYS_RESOURCE
56137
tmpfs:
57138
- /tmp
58139
- /run

0 commit comments

Comments
 (0)