[
https://issues.apache.org/jira/browse/YARN-5534?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Shane Kumpf updated YARN-5534:
------------------------------
Description: YARN-6623 added support in container-executor for admin
supplied Docker volume whitelists. This allows controlling which host
directories can be mounted into Docker containers launched by YARN. A read-only
and read-write whitelist was added. We now need the ability for users to supply
the mounts they require for their application, which will be validated against
the admin whitelist in container-executor. (was: Introduction
Mounting files or directories from the host is one way of passing configuration
and other information into a docker container.
We could allow the user to set a list of mounts in the environment of
ContainerLaunchContext (e.g. /dir1:/targetdir1,/dir2:/targetdir2).
These would be mounted read-only to the specified target locations. This has
been resolved in YARN-4595
2.Problem Definition
Bug mounting arbitrary volumes into a Docker container can be a security risk.
3.Possible solutions
one approach to provide safe mounts is to allow the cluster administrator to
configure a set of parent directories as white list mounting directories.
Add a property named yarn.nodemanager.volume-mounts.white-list, when container
executor do mount checking, only the allowed directories or sub-directories can
be mounted. )
> Allow user provided Docker volume mount list
> --------------------------------------------
>
> Key: YARN-5534
> URL: https://issues.apache.org/jira/browse/YARN-5534
> Project: Hadoop YARN
> Issue Type: Sub-task
> Components: yarn
> Reporter: luhuichun
> Assignee: Shane Kumpf
> Attachments: YARN-5534.001.patch, YARN-5534.002.patch,
> YARN-5534.003.patch
>
>
> YARN-6623 added support in container-executor for admin supplied Docker
> volume whitelists. This allows controlling which host directories can be
> mounted into Docker containers launched by YARN. A read-only and read-write
> whitelist was added. We now need the ability for users to supply the mounts
> they require for their application, which will be validated against the admin
> whitelist in container-executor.
--
This message was sent by Atlassian JIRA
(v6.4.14#64029)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]