Repository navigation
docs: agent 改用固定系统用户 monitor-agent - #1
Merged
Merged
Conversation
安全页的身份一栏改为专用系统用户,补充说明没开 nesting 的 LXC 容器里 systemd 跳过挂载类隔离、以及 agent 因此不用 DynamicUser。首页同步措辞, 卸载步骤加上 userdel monitor-agent。 对应 monitor-probe/monitor#5。
两个单元都明写了这一项:agent 在换掉 DynamicUser= 时补回(DynamicUser= 原本隐含它),hub 随后对齐。它由 seccomp 实现,不经挂载命名空间,所以 建不了命名空间的容器里仍然生效。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
对应 monitor-probe/monitor#5:agent 的 systemd 单元由
DynamicUser=yes改为User=monitor-agent。monitor-agent;补充说明没开 nesting 的 LXC 容器中 systemd 跳过挂载类隔离,以及 agent 因此不用DynamicUser;OpenRC 提示去掉对DynamicUser的引用userdel monitor-agentRestrictSUIDSGID。DynamicUser=原本隐含它,agent 单元在换掉DynamicUser=时明写补回,hub 单元随 feat: 掉线、流量、到期与登录通知(Telegram / Webhook) monitor#10 对齐npm run build通过。合并顺序:monitor-probe/monitor#8 已合,表里 hub 那一栏的
RestrictSUIDSGID要等 monitor-probe/monitor#10,所以本 PR 在 #10 之后合。