netdata/packaging/docker: Fix docker socket utilization, first pass (#6233)
* netdata/packaging/docker: Fix docker socket utilization, first pass 1) dont do anything if there is no socket available 2) fix the socket ownership after adding the new group 3) fix comments/copyrights * netdata/packaging: update README.md * netdata/packaging: adjust documentation * netdata/packaging: proper use of english @ README.md
Paul Emm. Katsoulakis committed
Jun 9, 2019 at 11:48 UTC
0a509325e3c967ae679ae2f27dc480edb5a1dc77
2 files changed
+48
-12
packaging/docker/README.md
+23
-4
@@ -50,14 +50,33 @@ services:
50
- /proc:/host/proc:ro
51
- /sys:/host/sys:ro
52
- /var/run/docker.sock:/var/run/docker.sock:ro
53
+ - /path/to/actual/docker/on/the/host:/usr/bin/docker
54
```
55
56
### Docker container names resolution
57
57
-If you want to have your container names resolved by netdata it needs to have access to docker group. To achive that just add environment variable `PGID=999` to netdata container, where `999` is a docker group id from your host. This number can be found by running:
58
-```bash
59
-grep docker /etc/group | cut -d ':' -f 3
60
-```
58
+If you want to have your container names resolved by netdata, you need to do two things:
59
+1) Make netdata user be part of the group that owns the socket.
60
+ To achieve that just add environment variable `PGID=[GROUP NUMBER]` to the netdata container,
61
+ where `[GROUP NUMBER]` is practically the group id of the group assigned to the docker socket, on your host.
62
+ This group number can be found by running the following (if socket group ownership is docker):
63
+ ```bash
64
+ grep docker /etc/group | cut -d ':' -f 3
65
+ ```
66
+
67
+2) Change docker socket access level to read/write like so:
68
+ from
69
+ ```
70
+ /var/run/docker.sock:/var/run/docker.sock:ro
71
+ ```
72
+
73
+ change to
74
+ ```
75
+ /var/run/docker.sock:/var/run/docker.sock:rw
76
+ ```
77
+
78
+**Important Note**: You should seriously consider the necessity of activating this option,
79
+as it grants to the netdata user access to the privileged socket connection of docker service
80
81
### Pass command line options to Netdata
82
packaging/docker/run.sh
+25
-8
@@ -1,16 +1,33 @@
1
-#!/bin/sh
2
-
3
-#set -e
1
+#!/usr/bin/env bash
2
+#
3
+# Entry point script for netdata
4
+#
5
+# Copyright: SPDX-License-Identifier: GPL-3.0-or-later
6
+#
7
+# Author : Pavlos Emm. Katsoulakis <paul@netdata.cloud>
8
+set -e
9
10
+echo "Netdata entrypoint script starting"
11
if [ ${RESCRAMBLE+x} ]; then
12
echo "Reinstalling all packages to get the latest Polymorphic Linux scramble"
13
apk upgrade --update-cache --available
14
fi
15
10
-if [ ${PGID+x} ]; then
11
- echo "Adding user netdata to group with id ${PGID}"
12
- addgroup -g "${PGID}" -S hostgroup 2>/dev/null
13
- sed -i "s/${PGID}:$/${PGID}:netdata/g" /etc/group
16
+DOCKER_USR="netdata"
17
+DOCKER_SOCKET="/var/run/docker.sock"
18
+DOCKER_GROUP="docker"
19
+
20
+if [ -S "${DOCKER_SOCKET}" ] && [ -n "${PGID}" ]; then
21
+ echo "Adding group with ID ${PGID} and name '${DOCKER_GROUP}'"
22
+ addgroup -g "${PGID}" "${DOCKER_GROUP}"
23
+
24
+ echo "Adding user '${DOCKER_USR}' to group '${DOCKER_GROUP}'"
25
+ sed -i "s/${DOCKER_GID}:$/${DOCKER_GID}:${DOCKER_USR}/g" /etc/group
26
+
27
+ echo "Adjusting ownership of mapped docker socket '${DOCKER_SOCKET}'"
28
+ chown "root:${DOCKER_GROUP}" "${DOCKER_SOCKET}"
29
fi
30
16
-exec /usr/sbin/netdata -u netdata -D -s /host -p "${NETDATA_PORT}" "$@"
31
+exec /usr/sbin/netdata -u "${DOCKER_USR}" -D -s /host -p "${NETDATA_PORT}" "$@"
32
+
33
+echo "Netdata entrypoint script, completed!"