From 64a8f9aeff7efcc3a9569123de7cf6dc3109cc80 Mon Sep 17 00:00:00 2001 From: mickael-hc <86245626+mickael-hc@users.noreply.github.com> Date: Fri, 18 Feb 2022 16:52:21 -0500 Subject: [PATCH] Remove --privileged recommendation from entrypoint script message (#14027) The use of the `--privileged` [flag](https://docs.docker.com/engine/reference/commandline/run/#options) is not recommended, as it does not adhere to the principle of least privilege. --- .release/docker/docker-entrypoint.sh | 2 +- scripts/docker/docker-entrypoint.sh | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.release/docker/docker-entrypoint.sh b/.release/docker/docker-entrypoint.sh index 81214cb9b6..3b72da25b7 100755 --- a/.release/docker/docker-entrypoint.sh +++ b/.release/docker/docker-entrypoint.sh @@ -91,7 +91,7 @@ if [ "$1" = 'vault' ]; then # In the case vault has been started in a container without IPC_LOCK privileges if ! vault -version 1>/dev/null 2>/dev/null; then - >&2 echo "Couldn't start vault with IPC_LOCK. Disabling IPC_LOCK, please use --privileged or --cap-add IPC_LOCK" + >&2 echo "Couldn't start vault with IPC_LOCK. Disabling IPC_LOCK, please use --cap-add IPC_LOCK" setcap cap_ipc_lock=-ep $(readlink -f $(which vault)) fi fi diff --git a/scripts/docker/docker-entrypoint.sh b/scripts/docker/docker-entrypoint.sh index 81214cb9b6..3b72da25b7 100755 --- a/scripts/docker/docker-entrypoint.sh +++ b/scripts/docker/docker-entrypoint.sh @@ -91,7 +91,7 @@ if [ "$1" = 'vault' ]; then # In the case vault has been started in a container without IPC_LOCK privileges if ! vault -version 1>/dev/null 2>/dev/null; then - >&2 echo "Couldn't start vault with IPC_LOCK. Disabling IPC_LOCK, please use --privileged or --cap-add IPC_LOCK" + >&2 echo "Couldn't start vault with IPC_LOCK. Disabling IPC_LOCK, please use --cap-add IPC_LOCK" setcap cap_ipc_lock=-ep $(readlink -f $(which vault)) fi fi