containerd: Enable enable_unprivileged_ports and enable_unprivileged_icmp by default

Signed-off-by: Olli Janatuinen <olli.janatuinen@gmail.com>
This commit is contained in:
Olli Janatuinen 2022-05-04 22:39:48 +02:00 committed by Brad Davidson
parent 31b8224f2a
commit 2968a83bc0

View File

@ -15,6 +15,8 @@ const ContainerdConfigTemplate = `
stream_server_address = "127.0.0.1"
stream_server_port = "10010"
enable_selinux = {{ .NodeConfig.SELinux }}
enable_unprivileged_ports = true
enable_unprivileged_icmp = true
{{- if .DisableCgroup}}
disable_cgroup = true