GRR v1.9.4: The Sisyphus Cgroup
- Verified with grootfs-release v0.26.0
The release mounts the container's cgroups at /sys/fs/cgroup
inside the container, in read-only mode, to allow containers to introspect their resource limits and usage.
Additionally, the permissions and ownership of /var/vcap/data/garden
have been hardened to work as securely as possible in combination with umask hardened stemcells.