mirror of
https://github.com/containers/podman.git
synced 2025-08-06 11:32:07 +08:00
Allow devs to set labels in container images for default capabilities.
This patch allows users to specify the list of capabilities required to run their container image. Setting a image/container label "io.containers.capabilities=setuid,setgid" tells podman that the contained image should work fine with just these two capabilties, instead of running with the default capabilities, podman will launch the container with just these capabilties. If the user or image specified capabilities that are not in the default set, the container will print an error message and will continue to run with the default capabilities. Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
This commit is contained in:
@ -60,8 +60,9 @@ Suppress output
|
||||
|
||||
## EXAMPLES
|
||||
|
||||
### Create image from container with entrypoint and label
|
||||
```
|
||||
$ podman commit --change CMD=/bin/bash --change ENTRYPOINT=/bin/sh --change LABEL=blue=image reverent_golick image-committed
|
||||
$ podman commit --change CMD=/bin/bash --change ENTRYPOINT=/bin/sh --change "LABEL blue=image" reverent_golick image-committed
|
||||
Getting image source signatures
|
||||
Copying blob sha256:b41deda5a2feb1f03a5c1bb38c598cbc12c9ccd675f438edc6acd815f7585b86
|
||||
25.80 MB / 25.80 MB [======================================================] 0s
|
||||
@ -72,26 +73,37 @@ Storing signatures
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8
|
||||
```
|
||||
|
||||
### Create image from container with commit message
|
||||
```
|
||||
$ podman commit -q --message "committing container to image" reverent_golick image-committed
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8
|
||||
$ podman commit -q --message "committing container to image"
|
||||
reverent_golick image-committed
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8 ```
|
||||
```
|
||||
|
||||
### Create image from container with author
|
||||
```
|
||||
$ podman commit -q --author "firstName lastName" reverent_golick image-committed
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8
|
||||
```
|
||||
|
||||
### Pause a running container while creating the image
|
||||
```
|
||||
$ podman commit -q --pause=false containerID image-committed
|
||||
$ podman commit -q --pause=true containerID image-committed
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8
|
||||
```
|
||||
|
||||
### Create an image from a container with a default image tag
|
||||
```
|
||||
$ podman commit containerID
|
||||
e3ce4d93051ceea088d1c242624d659be32cf1667ef62f1d16d6b60193e2c7a8
|
||||
```
|
||||
|
||||
### Create an image from container with default required capabilities are SETUID and SETGID
|
||||
```
|
||||
$ podman commit -q --change LABEL=io.containers.capabilities=setuid,setgid epic_nobel privimage
|
||||
400d31a3f36dca751435e80a0e16da4859beb51ff84670ce6bdc5edb30b94066
|
||||
```
|
||||
|
||||
## SEE ALSO
|
||||
podman(1), podman-run(1), podman-create(1)
|
||||
|
||||
|
Reference in New Issue
Block a user