mirror of
https://github.com/moby/moby.git
synced 2022-11-09 12:21:53 -05:00
Windows:Allow process isolation
Signed-off-by: John Howard <jhoward@microsoft.com>
This commit is contained in:
parent
5fbd82185f
commit
c907c2486c
1 changed files with 17 additions and 10 deletions
|
@ -193,12 +193,15 @@ func verifyContainerResources(resources *containertypes.Resources, isHyperv bool
|
||||||
// hostconfig and config structures.
|
// hostconfig and config structures.
|
||||||
func verifyPlatformContainerSettings(daemon *Daemon, hostConfig *containertypes.HostConfig, config *containertypes.Config, update bool) ([]string, error) {
|
func verifyPlatformContainerSettings(daemon *Daemon, hostConfig *containertypes.HostConfig, config *containertypes.Config, update bool) ([]string, error) {
|
||||||
warnings := []string{}
|
warnings := []string{}
|
||||||
|
osv := system.GetOSVersion()
|
||||||
hyperv := daemon.runAsHyperVContainer(hostConfig)
|
hyperv := daemon.runAsHyperVContainer(hostConfig)
|
||||||
if !hyperv && system.IsWindowsClient() && !system.IsIoTCore() {
|
|
||||||
// @engine maintainers. This block should not be removed. It partially enforces licensing
|
// On RS5, we allow (but don't strictly support) process isolation on Client SKUs.
|
||||||
// restrictions on Windows. Ping @jhowardmsft if there are concerns or PRs to change this.
|
// Prior to RS5, we don't allow process isolation on Client SKUs.
|
||||||
return warnings, fmt.Errorf("Windows client operating systems only support Hyper-V containers")
|
// @engine maintainers. This block should not be removed. It partially enforces licensing
|
||||||
|
// restrictions on Windows. Ping @jhowardmsft if there are concerns or PRs to change this.
|
||||||
|
if !hyperv && system.IsWindowsClient() && osv.Build < 17763 {
|
||||||
|
return warnings, fmt.Errorf("Windows client operating systems earlier than version 1809 can only run Hyper-V containers")
|
||||||
}
|
}
|
||||||
|
|
||||||
w, err := verifyContainerResources(&hostConfig.Resources, hyperv)
|
w, err := verifyContainerResources(&hostConfig.Resources, hyperv)
|
||||||
|
@ -592,9 +595,12 @@ func (daemon *Daemon) stats(c *container.Container) (*types.StatsJSON, error) {
|
||||||
// daemon to run in. This is only applicable on Windows
|
// daemon to run in. This is only applicable on Windows
|
||||||
func (daemon *Daemon) setDefaultIsolation() error {
|
func (daemon *Daemon) setDefaultIsolation() error {
|
||||||
daemon.defaultIsolation = containertypes.Isolation("process")
|
daemon.defaultIsolation = containertypes.Isolation("process")
|
||||||
// On client SKUs, default to Hyper-V. Note that IoT reports as a client SKU
|
osv := system.GetOSVersion()
|
||||||
// but it should not be treated as such.
|
|
||||||
if system.IsWindowsClient() && !system.IsIoTCore() {
|
// On client SKUs, default to Hyper-V. @engine maintainers. This
|
||||||
|
// should not be removed. Ping @jhowardmsft is there are PRs to
|
||||||
|
// to change this.
|
||||||
|
if system.IsWindowsClient() {
|
||||||
daemon.defaultIsolation = containertypes.Isolation("hyperv")
|
daemon.defaultIsolation = containertypes.Isolation("hyperv")
|
||||||
}
|
}
|
||||||
for _, option := range daemon.configStore.ExecOptions {
|
for _, option := range daemon.configStore.ExecOptions {
|
||||||
|
@ -613,10 +619,11 @@ func (daemon *Daemon) setDefaultIsolation() error {
|
||||||
daemon.defaultIsolation = containertypes.Isolation("hyperv")
|
daemon.defaultIsolation = containertypes.Isolation("hyperv")
|
||||||
}
|
}
|
||||||
if containertypes.Isolation(val).IsProcess() {
|
if containertypes.Isolation(val).IsProcess() {
|
||||||
if system.IsWindowsClient() && !system.IsIoTCore() {
|
if system.IsWindowsClient() && osv.Build < 17763 {
|
||||||
|
// On RS5, we allow (but don't strictly support) process isolation on Client SKUs.
|
||||||
// @engine maintainers. This block should not be removed. It partially enforces licensing
|
// @engine maintainers. This block should not be removed. It partially enforces licensing
|
||||||
// restrictions on Windows. Ping @jhowardmsft if there are concerns or PRs to change this.
|
// restrictions on Windows. Ping @jhowardmsft if there are concerns or PRs to change this.
|
||||||
return fmt.Errorf("Windows client operating systems only support Hyper-V containers")
|
return fmt.Errorf("Windows client operating systems earlier than version 1809 can only run Hyper-V containers")
|
||||||
}
|
}
|
||||||
daemon.defaultIsolation = containertypes.Isolation("process")
|
daemon.defaultIsolation = containertypes.Isolation("process")
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue