solaris getrlimit man, 如RLIMIT_CORE 运行时必须成生一个错误,如果任何值不能映射到内核接口。
soft 限制
hard 只有授权进程可以使用hard limit
Linux Process
apparmorProfile 可选 相见 AppArmor documentation.
capabilities 可选 运行时不能失败,如果容器配置需要过多的capabilities
effective
bounding
inheritable
premitted
ambient
noNewPrivileges 是否需要课外的privileges
oomScoreAdj
selinuxLabel
用户
用户是基于平台的设置
POSIX
用户结构包含
uid
gid
umask
addiotioanlGids
windows
username
主机名
主机名是容器的主机名,被其他容器内部进程可见。
Platform-specific configuration
linux (object, OPTIONAL) Linux-specific configuration. This MAY be set if the target platform of this spec is linux.
windows (object, OPTIONAL) Windows-specific configuration. This MUST be set if the target platform of this spec is windows.
solaris (object, OPTIONAL) Solaris-specific configuration. This MAY be set if the target platform of this spec is solaris.
vm (object, OPTIONAL) Virtual-machine-specific configuration. This MAY be set if the target platform and architecture of this spec support hardware virtualization.
zos (object, OPTIONAL) z/OS-specific configuration. This MAY be set if the target platform of this spec is zos.