From 663ee91eec01706008046c1df2c307716f9288db Mon Sep 17 00:00:00 2001
From: Giuseppe Scrivano <gscrivan@redhat.com>
Date: Wed, 22 Aug 2018 17:45:44 +0200
Subject: Fix Mount Propagation

Default mount propagation inside of containes should be private

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>

Closes: #1305
Approved by: mheon
---
 pkg/secrets/secrets.go | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

(limited to 'pkg/secrets')

diff --git a/pkg/secrets/secrets.go b/pkg/secrets/secrets.go
index 6f38f1fd5..be5642eba 100644
--- a/pkg/secrets/secrets.go
+++ b/pkg/secrets/secrets.go
@@ -243,7 +243,7 @@ func addSecretsFromMountsFile(filePath, mountLabel, containerWorkingDir, mountPr
 			Source:      filepath.Join(mountPrefix, ctrDir),
 			Destination: ctrDir,
 			Type:        "bind",
-			Options:     []string{"bind"},
+			Options:     []string{"bind", "private"},
 		}
 
 		mounts = append(mounts, m)
@@ -278,7 +278,7 @@ func addFIPSModeSecret(mounts *[]rspec.Mount, containerWorkingDir string) error
 			Source:      ctrDirOnHost,
 			Destination: secretsDir,
 			Type:        "bind",
-			Options:     []string{"bind"},
+			Options:     []string{"bind", "private"},
 		}
 		*mounts = append(*mounts, m)
 	}
-- 
cgit v1.2.3-54-g00ecf