https://www.kernel.org/doc/Documentation/cgroup-v1/devices.txt
cgroupã¯mknod (ç¹æ®ãã¡ã¤ã«ã®ä½æ) ãå¶éã§ããã
echo 'c 1:3 mr' > /sys/fs/cgroup/1/devices.allow
ãã㯠ãcgroup 1 ã«/dev/nullã®read and mknod ã®æ¨©éã追å ãããã¨ããæå³ã«ãªã
- æåã®cã¯typeã§a (all), c (char), or b (block) ã®3ã¤ããã
1:3
ã¯Major, minorããã¤ã¹çªå·ã詳細㯠ãã åç §- æå¾ã®mrã¯æ¨©éã§r (read), w (write), m (mknod)
åè: https://linuxcommand.net/mknod
Dockerã§è¨å®ããå ´å --device-cgroup-rule
ã使ã
docker run --rm --device-cgroup-rule 'c 1:3 mr' myapp