Add comment about Z flag for selinux

This commit is contained in:
Anthony Sottile 2017-11-02 15:30:08 -07:00
parent f0cf940cb5
commit 2e5b4fcf4c

View file

@ -82,6 +82,9 @@ def docker_cmd():
'docker', 'run', 'docker', 'run',
'--rm', '--rm',
'-u', '{}:{}'.format(os.getuid(), os.getgid()), '-u', '{}:{}'.format(os.getuid(), os.getgid()),
# https://docs.docker.com/engine/reference/commandline/run/#mount-volumes-from-container-volumes-from
# The `Z` option tells Docker to label the content with a private
# unshared label. Only the current container can use a private volume.
'-v', '{}:/src:rw,Z'.format(os.getcwd()), '-v', '{}:/src:rw,Z'.format(os.getcwd()),
'--workdir', '/src', '--workdir', '/src',
) )