You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Mar 9, 2022. It is now read-only.
What is the problem you're trying to solve
Some of the open source images have volume defined in dockerfile.
For containerd, it will create a dir at h host and bind mount it to container.
PR: #247
But this dir is not controlled, user may writes lots of datas to that mounted dir inside container to abuse the system.
Describe the solution you'd like
User need to do resource request in their pod spec
Kubelet can monitor the usage and take action like evict.
runtime can report the volume usage via CRI to kubelet.