Comments (7)
is there an update to this? we would like to move to using HNS ACLs instead of firewall rules on 1803, but this would block us
from hcsshim.
from hcsshim.
@sesmith177 thanks for reporting this. Can you give me some more details on your scenario? Are you trying to apply ACLs on individual endpoints or subnets? Are you wanting to create ACLs for Windows Server (shared kernel) containers or containers with Hyper-V Isolation. There were some known bugs with ACLs which we fixed in the latest version of Windows Server version 1803 which is due out later this month.
from hcsshim.
@JMesser81 we are applying ACLs on individual endpoints with shared kernel containers
from hcsshim.
@sesmith177 Thank you for the detailed report and code sample. @JMesser81 is correct that there are some known issues which were addressed in the latest version of Windows Server version 1803.
In the build you mentioned (17093.1000.amd64fre.rs_prerelease.180202-1400) there is a schema compatibility issue which may cause some ACLPolicy's from 1709 to fail to be applied. In your code example, the "Protocol" field is likely to be the cause of the issue as it is being passed by hcsshim as an integer, while the service in that particular build is expecting a string.
That issue was fixed and in the latest version of Windows Server 1803 (due out later this month) the protocol will once again be accepted as an integer value and your code sample should work as-is.
from hcsshim.
@natalieparellano looks like we can close this out? from talking with @aminjam 1803
is functioning as expected
from hcsshim.
Yes, this seems to be fixed in the latest build of windows server (1803).
from hcsshim.
Related Issues (20)
- github.com/golang/mock/mockgen now included into callers HOT 2
- Windows Containers for GUI application
- Dynamic add MappedPipe to Silo unable to read HOT 6
- v0.11: dependency on `containerd/cgroups` was accidentally rolled back from v3 to v1? HOT 2
- Error in launching Windows container with GPU device in Hyper-v isolation HOT 1
- Feature request: ConPTY subpackage
- GitHub is showing deprecated v0.10.0 as "Latest release" HOT 1
- Where is the HNS/HCS Endpoint default DNS config? HOT 5
- containerd-shim-runhcs-v1 can't parse runtimeoptions.v1.Options
- windows server 2022: create HNSEndpoint error:The provided policy configuration is invalid or missing parameters.
- Update open-policy-agent dependency HOT 1
- "failed to create containerd task: failed to create shim task: hcs::CreateComputeSystem xxxxxxx--cid--xxxxxxxx : Access is denied.: unknown"
- questions w.r.t. "osversion" package HOT 2
- choco install magicsplat-tcl-tk fails with hcsshim::ImportLayer failed in Win32 HOT 1
- hcsshim::PrepareLayer failed in Win32: The system cannot find the path specified. (0x3) on Docker Desktop 4.28.0 (139021) HOT 1
- ORMergeHives - public documentation?
- Cannot create New-BCContainer: hcsshim::ExpandScratchSize failed in Win32: The system cannot find the file specified. "c:\bcartifacts.cache:c:\dl"
- Process running within Docker Container throws OOM error but container doesn't report the error when exited HOT 1
- v0.12.1 hash was changed? HOT 6
- [Feature Request] Provide details when throwing errors
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from hcsshim.