@cryptotaxi247 / netdata-1 / commits / 0a509325e

netdata/packaging/docker: Fix docker socket utilization, first pass (#6233)

* netdata/packaging/docker: Fix docker socket utilization, first pass 1) dont do anything if there is no socket available 2) fix the socket ownership after adding the new group 3) fix comments/copyrights * netdata/packaging: update README.md * netdata/packaging: adjust documentation * netdata/packaging: proper use of english @ README.md

Paul Emm. Katsoulakis committed Jun 9, 2019 at 11:48 UTC 0a509325e3c967ae679ae2f27dc480edb5a1dc77
2 files changed +48 -12
packaging/docker/README.md
+23 -4
@@ -50,14 +50,33 @@ services:
50 - /proc:/host/proc:ro
51 - /sys:/host/sys:ro
52 - /var/run/docker.sock:/var/run/docker.sock:ro
53 + - /path/to/actual/docker/on/the/host:/usr/bin/docker
54 ```
55
56 ### Docker container names resolution
57
57 -If you want to have your container names resolved by netdata it needs to have access to docker group. To achive that just add environment variable `PGID=999` to netdata container, where `999` is a docker group id from your host. This number can be found by running:
58 -```bash
59 -grep docker /etc/group | cut -d ':' -f 3
60 -```
58 +If you want to have your container names resolved by netdata, you need to do two things:
59 +1) Make netdata user be part of the group that owns the socket.
60 + To achieve that just add environment variable `PGID=[GROUP NUMBER]` to the netdata container,
61 + where `[GROUP NUMBER]` is practically the group id of the group assigned to the docker socket, on your host.
62 + This group number can be found by running the following (if socket group ownership is docker):
63 + ```bash
64 + grep docker /etc/group | cut -d ':' -f 3
65 + ```
66 +
67 +2) Change docker socket access level to read/write like so:
68 + from
69 + ```
70 + /var/run/docker.sock:/var/run/docker.sock:ro
71 + ```
72 +
73 + change to
74 + ```
75 + /var/run/docker.sock:/var/run/docker.sock:rw
76 + ```
77 +
78 +**Important Note**: You should seriously consider the necessity of activating this option,
79 +as it grants to the netdata user access to the privileged socket connection of docker service
80
81 ### Pass command line options to Netdata
82
packaging/docker/run.sh
+25 -8
@@ -1,16 +1,33 @@
1 -#!/bin/sh
2 -
3 -#set -e
1 +#!/usr/bin/env bash
2 +#
3 +# Entry point script for netdata
4 +#
5 +# Copyright: SPDX-License-Identifier: GPL-3.0-or-later
6 +#
7 +# Author : Pavlos Emm. Katsoulakis <paul@netdata.cloud>
8 +set -e
9
10 +echo "Netdata entrypoint script starting"
11 if [ ${RESCRAMBLE+x} ]; then
12 echo "Reinstalling all packages to get the latest Polymorphic Linux scramble"
13 apk upgrade --update-cache --available
14 fi
15
10 -if [ ${PGID+x} ]; then
11 - echo "Adding user netdata to group with id ${PGID}"
12 - addgroup -g "${PGID}" -S hostgroup 2>/dev/null
13 - sed -i "s/${PGID}:$/${PGID}:netdata/g" /etc/group
16 +DOCKER_USR="netdata"
17 +DOCKER_SOCKET="/var/run/docker.sock"
18 +DOCKER_GROUP="docker"
19 +
20 +if [ -S "${DOCKER_SOCKET}" ] && [ -n "${PGID}" ]; then
21 + echo "Adding group with ID ${PGID} and name '${DOCKER_GROUP}'"
22 + addgroup -g "${PGID}" "${DOCKER_GROUP}"
23 +
24 + echo "Adding user '${DOCKER_USR}' to group '${DOCKER_GROUP}'"
25 + sed -i "s/${DOCKER_GID}:$/${DOCKER_GID}:${DOCKER_USR}/g" /etc/group
26 +
27 + echo "Adjusting ownership of mapped docker socket '${DOCKER_SOCKET}'"
28 + chown "root:${DOCKER_GROUP}" "${DOCKER_SOCKET}"
29 fi
30
16 -exec /usr/sbin/netdata -u netdata -D -s /host -p "${NETDATA_PORT}" "$@"
31 +exec /usr/sbin/netdata -u "${DOCKER_USR}" -D -s /host -p "${NETDATA_PORT}" "$@"
32 +
33 +echo "Netdata entrypoint script, completed!"