[ 
https://issues.apache.org/jira/browse/YARN-5534?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Shane Kumpf updated YARN-5534:
------------------------------
    Description: YARN-6623 added support in container-executor for admin 
supplied Docker volume whitelists. This allows controlling which host 
directories can be mounted into Docker containers launched by YARN. A read-only 
and read-write whitelist was added. We now need the ability for users to supply 
the mounts they require for their application, which will be validated against 
the admin whitelist in container-executor.  (was: Introduction 

Mounting files or directories from the host is one way of passing configuration 
and other information into a docker container. 
We could allow the user to set a list of mounts in the environment of 
ContainerLaunchContext (e.g. /dir1:/targetdir1,/dir2:/targetdir2). 
These would be mounted read-only to the specified target locations. This has 
been resolved in YARN-4595

2.Problem Definition

Bug mounting arbitrary volumes into a Docker container can be a security risk.

3.Possible solutions

one approach to provide safe mounts is to allow the cluster administrator to 
configure a set of parent directories as white list mounting directories.
 Add a property named yarn.nodemanager.volume-mounts.white-list, when container 
executor do mount checking, only the allowed directories or sub-directories can 
be mounted. )

> Allow user provided Docker volume mount list
> --------------------------------------------
>
>                 Key: YARN-5534
>                 URL: https://issues.apache.org/jira/browse/YARN-5534
>             Project: Hadoop YARN
>          Issue Type: Sub-task
>          Components: yarn
>            Reporter: luhuichun
>            Assignee: Shane Kumpf
>         Attachments: YARN-5534.001.patch, YARN-5534.002.patch, 
> YARN-5534.003.patch
>
>
> YARN-6623 added support in container-executor for admin supplied Docker 
> volume whitelists. This allows controlling which host directories can be 
> mounted into Docker containers launched by YARN. A read-only and read-write 
> whitelist was added. We now need the ability for users to supply the mounts 
> they require for their application, which will be validated against the admin 
> whitelist in container-executor.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to