make /var/log readonly

Expect apps to redirect logs of stdout/stderr

Part of #503
This commit is contained in:
Girish Ramakrishnan
2015-10-15 00:43:11 -07:00
parent a977597217
commit 5d389337cd
6 changed files with 6 additions and 71 deletions
+4 -2
View File
@@ -235,11 +235,13 @@ function createContainer(app, callback) {
ExposedPorts: exposedPorts,
Volumes: { // see also ReadonlyRootfs
'/tmp': {},
'/run': {},
'/var/log': {}
'/run': {}
}
};
// older versions wanted a writable /var/log
if (semver.lte(targetBoxVersion(app.manifest), '0.0.71')) containerOptions.Volumes['/var/log'] = {};
debugApp(app, 'Creating container for %s', app.manifest.dockerImage);
docker.createContainer(containerOptions, function (error, container) {