From bb582048d9e934c124f306b20fa8a25776c47392 Mon Sep 17 00:00:00 2001 From: "BARTRA, RICK" Date: Mon, 25 Mar 2019 11:29:46 -0400 Subject: [PATCH] Update documentation based on change to using unprivileged containers A recent change made most Divingbell Daemonsets run as unprivileged containers: https://review.openstack.org/#/c/639435/ Change-Id: If4e04368a3de3c7de7a3cf64692e5dd1294234b6 --- doc/source/index.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/doc/source/index.rst b/doc/source/index.rst index 8d8cff8..d94f36f 100644 --- a/doc/source/index.rst +++ b/doc/source/index.rst @@ -20,7 +20,7 @@ Design and Implementation ========================= -Divingbell DaemonSets run as privileged containers which mount the host +Divingbell DaemonSets mostly run as unprivileged containers which mount the host filesystem and chroot into that filesystem to enforce configuration and package state, or executes scripts in a namespace of ``systemd`` (PID=1). (The `diving bell `_ analogue can be thought of as something