unprivileged collection on containers

"Frank Ch. Eigler" <[email protected]> Wed, 1 Feb 2017 08:26:44 -0500
Newsgroups gmane.comp.sysutils.pcp
Message-ID <[email protected]>
Hi -

In online-hosted land, there is sometimes a need to collect data from
within a container about processes in itself and (as much as visible)
about the host.  On these systems, there is no opportunity to install
privileged software such as pmcd (not just without docker
--privileged; no intra-container root either) on the host, so the
ambitious agent-less container capabilities of pcp are moot.

One can imagine a pmcd mode that starts up without root.  No pmdaroot
of course, nor any setuid-capable pmda*.  All the needed pmdas would
run as the native uid of the container, and would necessarily expose
only local-perspective state.

Is this something you imagine being compatible with "the pcp vision"?
If someone were to need this in a hurry, what would you say?

In this world, of course host-side or cross-container data is not
directly available.  One'd need pmmgr or whatever farming (or
hypothetical federation) facility to merge together data from
unprivileged pmcds running in the containers.

- FChE

-=-=-=-=-=-=-=-=-=-=-=-
Groups.io Links:

You receive all messages sent to this group.

View/Reply Online (#15057): https://groups.io/g/pcp/message/15057
View All Messages In Topic (1): https://groups.io/g/pcp/topic/4296923
Mute This Topic: https://groups.io/mt/4296923?uid=174580
New Topic: https://groups.io/g/pcp/post
-=-=-
pcp mailing list
[email protected]
https://groups.io/g/pcp/messages
-=-=-
Change Your Subscription: https://groups.io/g/pcp/editsub?uid=174580
Group Home: https://groups.io/g/pcp
Contact Group Owner: [email protected]
Terms of Service: https://groups.io/static/tos
Unsubscribe: https://groups.io/g/pcp/leave/354243/563757577/xyzzy
-=-=-=-=-=-=-=-=-=-=-=-