Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type NativeHook ¶
type NativeHook struct {
// Name for the hook, will be set to the hook filename if not specified.
Name string `json:"name"`
// Version of the hook structure - 1.0.0 is expected
Version string `json:"version"`
// Hook as an OCI runtime-spec Hook struct
Hook specs.Hook `json:"hook"`
// When the hook should run
When cchooks.When `json:"when"`
// Stages in the container lifecycle at which the hook should run
Stages []string `json:"stages"`
// Privileged indicates the hook should be executed only in setuid, and with escalated privilege.
Privileged bool `json:"privileged"`
}
NativeHook represents a hook that can be executed by the native runtime. It has the same basic structure as the containers/common current.Hook type, with the addition of a boolean 'Privileged' field that marks the hook for privileged escalation in the setuid flow, and a string 'Name' field.
func LoadNativeHooks ¶
func LoadNativeHooks(privileged bool) ([]NativeHook, error)
LoadNativeHooks loads all hooks from JSON files in the configuration directory. If privileged is false, hooks that specify `Privileged: true` are skipped, and there are no ownership checks. If privileged is true, all hooks are loaded and must have `root:root` ownership.
func (*NativeHook) Run ¶
func (n *NativeHook) Run(state specs.State, allowPrivileged bool) error
Run executes the NativeHook binary with configured args and env. If allowPrivileged is false, a hook with `Privileged=true` will refuse to run. If allowPrivileged is true, a hook with `Privileged=true` will be run as root. A JSON OCI runtime-spec state structure is passed over STDIN. A non-standard `SINGULARITY_CONTAINER_PID` env var is added for the convenience of hooks that would otherwise need to parse the PID from the state JSON. A `SINGULARITY_HOOK_PRIVILEGED` env var is set if the hook is being run with privilege.
func (*NativeHook) Validate ¶
func (n *NativeHook) Validate() error
Validate checks that a NativeHook is supported by the runtime. At present, only poststart hooks that run always are supported.