diff options
| author | Ophestra <cat@gensokyo.uk> | 2025-06-25 03:59:52 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2025-06-25 04:57:41 +0900 |
| commit | 87e008d56de974947ebb99c2cc40b25d3c2cf43e (patch) | |
| tree | 31791911e5226d6ec04e3fac7d91b0bf53e63aa5 /fst/container.go | |
| parent | 399207321265307bb15f37d867f9370cd51c82a8 (diff) | |
treewide: rename to hakurei
Fortify makes little sense for a container tool.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'fst/container.go')
| -rw-r--r-- | fst/container.go | 59 |
1 files changed, 0 insertions, 59 deletions
diff --git a/fst/container.go b/fst/container.go deleted file mode 100644 index 1190caa3..00000000 --- a/fst/container.go +++ /dev/null @@ -1,59 +0,0 @@ -package fst - -import ( - "git.gensokyo.uk/security/fortify/sandbox/seccomp" -) - -type ( - // ContainerConfig describes the container configuration baseline to which the app implementation adds upon. - ContainerConfig struct { - // container hostname - Hostname string `json:"hostname,omitempty"` - - // extra seccomp flags - Seccomp seccomp.FilterOpts `json:"seccomp"` - // allow ptrace and friends - Devel bool `json:"devel,omitempty"` - // allow userns creation in container - Userns bool `json:"userns,omitempty"` - // share host net namespace - Net bool `json:"net,omitempty"` - // allow dangerous terminal I/O - Tty bool `json:"tty,omitempty"` - // allow multiarch - Multiarch bool `json:"multiarch,omitempty"` - - // initial process environment variables - Env map[string]string `json:"env"` - // map target user uid to privileged user uid in the user namespace - MapRealUID bool `json:"map_real_uid"` - - // pass through all devices - Device bool `json:"device,omitempty"` - // container host filesystem bind mounts - Filesystem []*FilesystemConfig `json:"filesystem"` - // create symlinks inside container filesystem - Link [][2]string `json:"symlink"` - - // read-only /etc directory - Etc string `json:"etc,omitempty"` - // automatically set up /etc symlinks - AutoEtc bool `json:"auto_etc"` - // cover these paths or create them if they do not already exist - Cover []string `json:"cover"` - } - - // FilesystemConfig is an abstract representation of a bind mount. - FilesystemConfig struct { - // mount point in container, same as src if empty - Dst string `json:"dst,omitempty"` - // host filesystem path to make available to the container - Src string `json:"src"` - // do not mount filesystem read-only - Write bool `json:"write,omitempty"` - // do not disable device files - Device bool `json:"dev,omitempty"` - // fail if the bind mount cannot be established for any reason - Must bool `json:"require,omitempty"` - } -) |
