Open olifre opened 6 years ago
Note there would be an error in either case then (just the error would happen when runc
noticed that the bind-mount is to a non-existent path). In addition, "readonly": true
refers to the final setup of the container, not the context in which it was started.
But we have previously made changes to work better with containers started on a read-only root filesystem (such as #1125).
Running a rootless container and specifying a
mounts
section with adestination
which does not yet exist in therootfs
, anmkdir
of the missing bind mount point is performed.Example for a read-only FS:
If the FS was not really read-only, a directory would be created (and never cleaned up).