-
Notifications
You must be signed in to change notification settings - Fork 599
Open
Description
currently runc run has a command line option --no-new-keyring which disables the creation of an isolated kernel keyring for the process. This is kind of weird - I think this should be part of the OCI spec as it is just a specification of resource allocation, like having a new namespace. I can write up a proposal for this; obviously though this will be a breaking change so want to know what anyone else thinks.
Metadata
Metadata
Assignees
Labels
No labels