From 16ac6ada664f498f711a7dd894233ccd7fe0b6aa Mon Sep 17 00:00:00 2001 From: Simone Gotti Date: Wed, 13 Mar 2019 12:11:46 +0100 Subject: [PATCH] runservice: add privileged containers options --- internal/config/config.go | 1 + internal/runconfig/runconfig.go | 1 + internal/services/runservice/executor/driver/docker.go | 1 + internal/services/runservice/executor/driver/driver.go | 1 + internal/services/runservice/executor/executor.go | 1 + internal/services/runservice/types/types.go | 5 ++++- 6 files changed, 9 insertions(+), 1 deletion(-) diff --git a/internal/config/config.go b/internal/config/config.go index 79279d5..884ed37 100644 --- a/internal/config/config.go +++ b/internal/config/config.go @@ -70,6 +70,7 @@ type Container struct { Image string `yaml:"image,omitempty"` Environment map[string]string `yaml:"environment,omitempty"` User string `yaml:"user"` + Privileged bool `yaml:"privileged"` } type Pipeline struct { diff --git a/internal/runconfig/runconfig.go b/internal/runconfig/runconfig.go index a3944b9..0cd0c4f 100644 --- a/internal/runconfig/runconfig.go +++ b/internal/runconfig/runconfig.go @@ -36,6 +36,7 @@ func genRuntime(c *config.Config, runtimeName string) *rstypes.Runtime { Image: cc.Image, Environment: cc.Environment, User: cc.User, + Privileged: cc.Privileged, }) } return &rstypes.Runtime{ diff --git a/internal/services/runservice/executor/driver/docker.go b/internal/services/runservice/executor/driver/docker.go index 94be9c3..e6da9cd 100644 --- a/internal/services/runservice/executor/driver/docker.go +++ b/internal/services/runservice/executor/driver/docker.go @@ -150,6 +150,7 @@ func (d *DockerDriver) NewPod(ctx context.Context, podConfig *PodConfig) (Pod, e }, &container.HostConfig{ Binds: []string{fmt.Sprintf("%s:%s", d.initVolumeHostDir, podConfig.InitVolumeDir)}, ReadonlyPaths: []string{fmt.Sprintf("%s:%s", d.initVolumeHostDir, podConfig.InitVolumeDir)}, + Privileged: containerConfig.Privileged, }, nil, "") if err != nil { return nil, err diff --git a/internal/services/runservice/executor/driver/driver.go b/internal/services/runservice/executor/driver/driver.go index 9184d00..92d2223 100644 --- a/internal/services/runservice/executor/driver/driver.go +++ b/internal/services/runservice/executor/driver/driver.go @@ -76,6 +76,7 @@ type ContainerConfig struct { WorkingDir string Image string User string + Privileged bool RegistryAuth string } diff --git a/internal/services/runservice/executor/executor.go b/internal/services/runservice/executor/executor.go index da157b5..fb12f65 100644 --- a/internal/services/runservice/executor/executor.go +++ b/internal/services/runservice/executor/executor.go @@ -449,6 +449,7 @@ func (e *Executor) executeTask(ctx context.Context, et *types.ExecutorTask) { Env: et.Containers[0].Environment, WorkingDir: et.WorkingDir, User: et.Containers[0].User, + Privileged: et.Containers[0].Privileged, }, }, } diff --git a/internal/services/runservice/types/types.go b/internal/services/runservice/types/types.go index 07c823b..45c3a01 100644 --- a/internal/services/runservice/types/types.go +++ b/internal/services/runservice/types/types.go @@ -387,7 +387,9 @@ type ExecutorTask struct { WorkingDir string `json:"working_dir,omitempty"` Shell string `json:"shell,omitempty"` User string `json:"user,omitempty"` - Steps []interface{} `json:"steps,omitempty"` + Privileged bool `yaml:"privileged"` + + Steps []interface{} `json:"steps,omitempty"` Status ExecutorTaskStatus `json:"status,omitempty"` SetupError string `fail_reason:"setup_error,omitempty"` @@ -422,6 +424,7 @@ type Container struct { Image string `json:"image,omitempty"` Environment map[string]string `json:"environment,omitempty"` User string `json:"user,omitempty"` + Privileged bool `json:"privileged"` } type Workspace []WorkspaceLevel