Open ruifung opened 1 year ago
you can of course build your own version of the system extension. if there are valuable config options, let's have them discussed here and how to make that configuration available.
From my perusal of the gvisor documentation, (and my own experiments with it), A few options come to mind that would be good to be potentially exposed as either part of the default runsc handler configuration, or perhaps even as additional handler configurations.
All of the above would involve either modifying the runsc.toml file, or potentially additional container runtime entries too if say you wanted to have a separate runtimeClass that completely disables networking for whatever reason. Or conversely, passthrough the host network stack.
Or is the only way to make a separate system extension / modify the existing one?
Just asking in case I need to change the gvisor configuration for example, enabling root fs overlay, or changing the platform used in gvisor.