MuToolkit Yekugadzirisa Isolated Linux Docker Containers
Kusagadzikana kunobvumira mafaera kuti abviswe kubva mumudziyo kuenda kune inopokana chikamu cheiyo host system's faira system paunenge uchiita iyo "docker cp" yekuraira. Kudhirowa kwefaira kunoitwa nekodzero dzemidzi, izvo zvinoita kuti zvikwanise kuverenga kana kunyora chero mafaera munzvimbo inotambira, izvo zvinokwana kuwana kutonga kweiyo host system (semuenzaniso, unogona kunyora pamusoro /etc/shadow).
Kurwiswa uku kunogona kuitwa chete kana maneja aita "docker cp" kuraira kukopa mafaera kuenda kana kubva mumudziyo. Nekudaro, anorwisa anofanirwa kutendesa Docker maneja nezve kukosha kwekuita oparesheni iyi uye kufanotaura nzira inoshandiswa pakukopa. Kune rumwe rutivi, kurwiswa kunogona kuitwa, semuenzaniso, kana makore masevhisi achipa zvishandiso zvekukopa mafaera ekugadzirisa mumudziyo, wakavakwa uchishandisa "docker cp" kuraira.
Dambudziko rinokonzerwa nekukanganisika mukushandiswa kwebasa racho
Sezvo hwindo renguva rekuti mamiriro emujaho aitike akaganhurirwa zvakanyanya mukugadzirira
Nekuita kopi yekuvhiya mumudziyo, unogona kuwana inodzokororwa faira rekunyora kurwisa pane iyo host system mune mashoma iterations. Iko mukana wekurwiswa unokonzerwa nekuti kana uchikopa mumudziyo, iyo "chrootarchive" pfungwa inoshandiswa, zvichienderana nekuti iyo archive.go process inobvisa iyo archive kwete mu chroot yemudzi wemudziyo, asi mu chroot ye dhairekitori yevabereki yenzira inotangwa, inodzorwa neanorwisa, uye haimise kuurayiwa kwemudziyo (chroot inoshandiswa sechiratidzo chekushandisa mamiriro emujaho).
Source: opennet.ru