Struct podman_api_stubs::models::ContainerSecurityConfig
source · [−]pub struct ContainerSecurityConfig {Show 17 fields
pub apparmor_profile: Option<String>,
pub cap_add: Option<Vec<String>>,
pub cap_drop: Option<Vec<String>>,
pub groups: Option<Vec<String>>,
pub idmappings: Option<IdMappingOptions>,
pub mask: Option<Vec<String>>,
pub no_new_privileges: Option<bool>,
pub privileged: Option<bool>,
pub procfs_opts: Option<Vec<String>>,
pub read_only_filesystem: Option<bool>,
pub seccomp_policy: Option<String>,
pub seccomp_profile_path: Option<String>,
pub selinux_opts: Option<Vec<String>>,
pub umask: Option<String>,
pub unmask: Option<Vec<String>>,
pub user: Option<String>,
pub userns: Option<Namespace>,
}
Expand description
ContainerSecurityConfig is a container’s security features, including SELinux, Apparmor, and Seccomp.
Fields
apparmor_profile: Option<String>
ApparmorProfile is the name of the Apparmor profile the container will use. Optional.
cap_add: Option<Vec<String>>
CapAdd are capabilities which will be added to the container. Conflicts with Privileged. Optional.
cap_drop: Option<Vec<String>>
CapDrop are capabilities which will be removed from the container. Conflicts with Privileged. Optional.
groups: Option<Vec<String>>
Groups are a list of supplemental groups the container’s user will be granted access to. Optional.
idmappings: Option<IdMappingOptions>
mask: Option<Vec<String>>
Mask is the path we want to mask in the container. This masks the paths given in addition to the default list. Optional
no_new_privileges: Option<bool>
NoNewPrivileges is whether the container will set the no new privileges flag on create, which disables gaining additional privileges (e.g. via setuid) in the container.
privileged: Option<bool>
Privileged is whether the container is privileged. Privileged does the following: Adds all devices on the system to the container. Adds all capabilities to the container. Disables Seccomp, SELinux, and Apparmor confinement. (Though SELinux can be manually re-enabled). TODO: this conflicts with things. TODO: this does more.
procfs_opts: Option<Vec<String>>
ProcOpts are the options used for the proc mount.
read_only_filesystem: Option<bool>
ReadOnlyFilesystem indicates that everything will be mounted as read-only
seccomp_policy: Option<String>
SeccompPolicy determines which seccomp profile gets applied the container. valid values: empty,default,image
seccomp_profile_path: Option<String>
SeccompProfilePath is the path to a JSON file containing the container’s Seccomp profile. If not specified, no Seccomp profile will be used. Optional.
selinux_opts: Option<Vec<String>>
SelinuxProcessLabel is the process label the container will use. If SELinux is enabled and this is not specified, a label will be automatically generated if not specified. Optional.
umask: Option<String>
Umask is the umask the init process of the container will be run with.
unmask: Option<Vec<String>>
Unmask is the path we want to unmask in the container. To override all the default paths that are masked, set unmask=ALL.
user: Option<String>
User is the user the container will be run as. Can be given as a UID or a username; if a username, it will be resolved within the container, using the container’s /etc/passwd. If unset, the container will be run as root. Optional.
userns: Option<Namespace>
Trait Implementations
sourceimpl Clone for ContainerSecurityConfig
impl Clone for ContainerSecurityConfig
sourcefn clone(&self) -> ContainerSecurityConfig
fn clone(&self) -> ContainerSecurityConfig
Returns a copy of the value. Read more
1.0.0 · sourcefn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from source
. Read more
sourceimpl Debug for ContainerSecurityConfig
impl Debug for ContainerSecurityConfig
sourceimpl<'de> Deserialize<'de> for ContainerSecurityConfig
impl<'de> Deserialize<'de> for ContainerSecurityConfig
sourcefn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error> where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error> where
__D: Deserializer<'de>,
Deserialize this value from the given Serde deserializer. Read more
sourceimpl PartialEq<ContainerSecurityConfig> for ContainerSecurityConfig
impl PartialEq<ContainerSecurityConfig> for ContainerSecurityConfig
sourcefn eq(&self, other: &ContainerSecurityConfig) -> bool
fn eq(&self, other: &ContainerSecurityConfig) -> bool
This method tests for self
and other
values to be equal, and is used
by ==
. Read more
sourcefn ne(&self, other: &ContainerSecurityConfig) -> bool
fn ne(&self, other: &ContainerSecurityConfig) -> bool
This method tests for !=
.
sourceimpl Serialize for ContainerSecurityConfig
impl Serialize for ContainerSecurityConfig
impl StructuralPartialEq for ContainerSecurityConfig
Auto Trait Implementations
impl RefUnwindSafe for ContainerSecurityConfig
impl Send for ContainerSecurityConfig
impl Sync for ContainerSecurityConfig
impl Unpin for ContainerSecurityConfig
impl UnwindSafe for ContainerSecurityConfig
Blanket Implementations
sourceimpl<T> BorrowMut<T> for T where
T: ?Sized,
impl<T> BorrowMut<T> for T where
T: ?Sized,
const: unstable · sourcefn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more