- Sort Score
- Result 10 results
- Languages All
Results 1 - 10 of 26 for syys (0.15 sec)
-
manifests/charts/istio-cni/templates/daemonset.yaml
- NET_RAW # CAP_SYS_ADMIN is required for both ambient and repair, in order to open # network namespaces in `/proc` to obtain descriptors for entering pod netnamespaces. # There does not appear to be a more granular capability for this. - SYS_ADMIN {{- if .Values.cni.seccompProfile }} seccompProfile:
Others - Registered: Wed Mar 20 22:53:08 GMT 2024 - Last Modified: Wed Feb 28 17:29:38 GMT 2024 - 9.4K bytes - Viewed (0) -
manifests/charts/ztunnel/templates/daemonset.yaml
capabilities: drop: - ALL add: # See https://man7.org/linux/man-pages/man7/capabilities.7.html - NET_ADMIN # Required for TPROXY and setsockopt - SYS_ADMIN # Required for `setns` - doing things in other netns - NET_RAW # Required for RAW/PACKET sockets, TPROXY readOnlyRootFilesystem: true runAsGroup: 1337 runAsNonRoot: false
Others - Registered: Wed Mar 20 22:53:08 GMT 2024 - Last Modified: Fri Jan 26 20:34:28 GMT 2024 - 5K bytes - Viewed (0) -
cni/pkg/nodeagent/fakes_test.go
fi, err := f.File.Stat() if err != nil { return nil, err } return &fakeFileFakeFI{FileInfo: fi}, nil } type fakeFileFakeFI struct { fs.FileInfo } func (f *fakeFileFakeFI) Sys() any { return &syscall.Stat_t{Ino: 1} } // Open opens the named file. // When Open returns an error, it should be of type *PathError // with the Op field set to "open", the Path field set to name,
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Fri Apr 12 21:47:31 GMT 2024 - 3.9K bytes - Viewed (0) -
README.md
Plain Text - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Fri Jan 26 15:28:59 GMT 2024 - 6.6K bytes - Viewed (0) -
manifests/charts/gateways/istio-egress/values.yaml
# For example: # podAntiAffinityLabelSelector: # - key: security # operator: In # values: S1,S2 # topologyKey: "kubernetes.io/hostname" # This pod anti-affinity rule says that the pod requires not to be scheduled # onto a node if that node is already running a pod with label having key # "security" and value "S1". podAntiAffinityLabelSelector: []
Others - Registered: Wed Apr 24 22:53:08 GMT 2024 - Last Modified: Tue Feb 27 16:55:16 GMT 2024 - 12.4K bytes - Viewed (0) -
manifests/charts/gateways/istio-ingress/values.yaml
# For example: # podAntiAffinityLabelSelector: # - key: security # operator: In # values: S1,S2 # topologyKey: "kubernetes.io/hostname" # This pod anti-affinity rule says that the pod requires not to be scheduled # onto a node if that node is already running a pod with label having key # "security" and value "S1". podAntiAffinityLabelSelector: []
Others - Registered: Wed Apr 24 22:53:08 GMT 2024 - Last Modified: Tue Feb 27 16:55:16 GMT 2024 - 13K bytes - Viewed (0) -
manifests/addons/dashboards/pilot-dashboard.json
"type": "prometheus", "uid": "${datasource}" }, "expr": "go_memstats_heap_sys_bytes{app=\"istiod\"}", "format": "time_series", "hide": true, "intervalFactor": 2, "legendFormat": "heap sys", "refId": "A" }, { "datasource": { "type": "prometheus",
Json - Registered: Wed Apr 24 22:53:08 GMT 2024 - Last Modified: Wed Mar 27 03:47:04 GMT 2024 - 61K bytes - Viewed (0) -
cni/pkg/repair/netns.go
package repair import ( "fmt" "math" "net" "strconv" netns "github.com/containernetworking/plugins/pkg/ns" "github.com/prometheus/procfs" "github.com/vishvananda/netlink" "golang.org/x/sys/unix" corev1 "k8s.io/api/core/v1" "istio.io/istio/pkg/log" ) func getPidNamespace(pid int) string { return "/host/proc/" + strconv.Itoa(pid) + "/ns/net" }
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Wed Dec 20 22:14:13 GMT 2023 - 4.8K bytes - Viewed (0) -
cni/pkg/nodeagent/net.go
// See the License for the specific language governing permissions and // limitations under the License. package nodeagent import ( "context" "errors" "fmt" "net/netip" "golang.org/x/sys/unix" corev1 "k8s.io/api/core/v1" "k8s.io/apimachinery/pkg/types" "istio.io/istio/cni/pkg/ipset" "istio.io/istio/cni/pkg/iptables" "istio.io/istio/cni/pkg/util" istiolog "istio.io/istio/pkg/log"
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 12.2K bytes - Viewed (1) -
cni/pkg/iptables/iptables_linux.go
// limitations under the License. package iptables import ( "errors" "fmt" "net" "github.com/vishvananda/netlink" "golang.org/x/sys/unix" ) func AddInpodMarkIPRule(cfg *Config) error { err := forEachInpodMarkIPRule(cfg, netlink.RuleAdd) if errors.Is(err, unix.EEXIST) { log.Debugf("Ignoring exists error adding inpod mark ip rule: %v", err)
Go - Registered: Wed May 01 22:53:12 GMT 2024 - Last Modified: Tue Apr 30 22:24:38 GMT 2024 - 3.3K bytes - Viewed (0)