@@ -210,10 +210,10 @@ func (d *DockerClient) CreateWorker(ctx context.Context, c WorkerContainerConfig
|
||||
name := url.QueryEscape(c.Name)
|
||||
body := map[string]any{
|
||||
"Image": c.Image,
|
||||
// Named Docker volumes are root-owned when first mounted. Managed workers
|
||||
// therefore run uid 0 only inside their own locked-down container so they
|
||||
// can create the 0600 identity file. They receive no Docker socket, all
|
||||
// Linux capabilities are dropped and the image root filesystem is read-only.
|
||||
// Named Docker volumes are root-owned when first mounted, and identities
|
||||
// created by older releases may be owned by a different UID. The dedicated
|
||||
// worker image starts as uid 0 only for its tiny ownership-normalization
|
||||
// entrypoint and immediately drops to the unprivileged app user.
|
||||
"User": "0:0",
|
||||
"Cmd": []string{"-url", c.GameURL, "-identity", "/identity/identity.json", "-non-interactive", "-quiet", "-task", c.TaskID, "-beacon-path", c.BeaconPath},
|
||||
"Env": []string{
|
||||
@@ -228,10 +228,13 @@ func (d *DockerClient) CreateWorker(ctx context.Context, c WorkerContainerConfig
|
||||
"NetworkMode": c.Network,
|
||||
"ReadonlyRootfs": true,
|
||||
"CapDrop": []string{"ALL"},
|
||||
"SecurityOpt": []string{"no-new-privileges"},
|
||||
"PidsLimit": 128,
|
||||
"Memory": 256 * 1024 * 1024,
|
||||
"NanoCpus": int64(1_000_000_000),
|
||||
// Bootstrap-only capabilities: the image entrypoint fixes ownership of
|
||||
// /identity and then su-exec permanently switches to uid/gid app.
|
||||
"CapAdd": []string{"CHOWN", "DAC_OVERRIDE", "SETUID", "SETGID"},
|
||||
"SecurityOpt": []string{"no-new-privileges"},
|
||||
"PidsLimit": 128,
|
||||
"Memory": 256 * 1024 * 1024,
|
||||
"NanoCpus": int64(1_000_000_000),
|
||||
},
|
||||
}
|
||||
// A dedicated worker image already declares /app/neuralhunt-client as its
|
||||
|
||||
Reference in New Issue
Block a user