Merge pull request #111924 from saschagrunert/cri-o-oci-hook

nixos/cri-o: add OCI seccomp bpf hook support
This commit is contained in:
adisbladis 2021-02-06 12:03:44 +01:00 committed by GitHub
commit 6caa6cb3f5
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -103,7 +103,10 @@ in
cgroup_manager = "systemd"
log_level = "${cfg.logLevel}"
pinns_path = "${cfg.package}/bin/pinns"
hooks_dir = []
hooks_dir = [
${lib.optionalString config.virtualisation.containers.ociSeccompBpfHook.enable
''"${config.boot.kernelPackages.oci-seccomp-bpf-hook}",''}
]
${optionalString (cfg.runtime != null) ''
default_runtime = "${cfg.runtime}"