unprivileged collection on containers
"Frank Ch. Eigler" <[email protected]> Wed, 1 Feb 2017 08:26:44 -0500
| Newsgroups | gmane.comp.sysutils.pcp |
|---|---|
| Message-ID | <[email protected]> |
Hi - In online-hosted land, there is sometimes a need to collect data from within a container about processes in itself and (as much as visible) about the host. On these systems, there is no opportunity to install privileged software such as pmcd (not just without docker --privileged; no intra-container root either) on the host, so the ambitious agent-less container capabilities of pcp are moot. One can imagine a pmcd mode that starts up without root. No pmdaroot of course, nor any setuid-capable pmda*. All the needed pmdas would run as the native uid of the container, and would necessarily expose only local-perspective state. Is this something you imagine being compatible with "the pcp vision"? If someone were to need this in a hurry, what would you say? In this world, of course host-side or cross-container data is not directly available. One'd need pmmgr or whatever farming (or hypothetical federation) facility to merge together data from unprivileged pmcds running in the containers. - FChE -=-=-=-=-=-=-=-=-=-=-=- Groups.io Links: You receive all messages sent to this group. View/Reply Online (#15057): https://groups.io/g/pcp/message/15057 View All Messages In Topic (1): https://groups.io/g/pcp/topic/4296923 Mute This Topic: https://groups.io/mt/4296923?uid=174580 New Topic: https://groups.io/g/pcp/post -=-=- pcp mailing list [email protected] https://groups.io/g/pcp/messages -=-=- Change Your Subscription: https://groups.io/g/pcp/editsub?uid=174580 Group Home: https://groups.io/g/pcp Contact Group Owner: [email protected] Terms of Service: https://groups.io/static/tos Unsubscribe: https://groups.io/g/pcp/leave/354243/563757577/xyzzy -=-=-=-=-=-=-=-=-=-=-=-