Skip to content

GRR v1.9.4: The Sisyphus Cgroup

Compare
Choose a tag to compare
@garden-gnome garden-gnome released this 28 Sep 11:21
· 2590 commits to develop since this release

The release mounts the container's cgroups at /sys/fs/cgroup inside the container, in read-only mode, to allow containers to introspect their resource limits and usage.

Additionally, the permissions and ownership of /var/vcap/data/garden have been hardened to work as securely as possible in combination with umask hardened stemcells.