Nova: Mount cgroups read only
This PS updates the mount options for the nova-compute pod to mount cgroups as read only within the pod. Change-Id: I82e958c2865029cd4a093f62614a1e878075098a Signed-off-by: Pete Birley <pete@port.direct>
This commit is contained in:
parent
c20d358c60
commit
bb7b973258
@ -248,6 +248,7 @@ spec:
|
||||
mountPath: /run
|
||||
- name: cgroup
|
||||
mountPath: /sys/fs/cgroup
|
||||
readOnly: true
|
||||
- name: pod-shared
|
||||
mountPath: /tmp/pod-shared
|
||||
- name: machine-id
|
||||
|
Loading…
x
Reference in New Issue
Block a user