Commit Graph
1 Commits
Author SHA1 Message Date
Jonah BackandYusuke Kuoka 8c42f99d0b feat: avoid setting privileged flag if seLinuxOptions is not null (#599)
Sets the privileged flag to false if SELinuxOptions are present/defined. This is needed because containerd treats SELinux and Privileged controls as mutually exclusive. Also see https://github.com/containerd/cri/blob/aa2d5a97c/pkg/server/container_create.go#L164.

This allows users who use SELinux for managing privileged processes to use GH Actions - otherwise, based on the SELinux policy, the Docker in Docker container might not be privileged enough. 

Signed-off-by: Jonah Back <[email protected]>
Co-authored-by: Yusuke Kuoka <[email protected]>
2021-06-04 08:59:11 +09:00