Replies: 1 comment
|
There is currently no persistent per-path allowlist in #!/bin/sh
exec docker buildx bake --allow 'fs.read=/Users/milas/.netrc' "$@"This is intentionally separate from BuildKit daemon entitlements such as |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
I mount files outside the build context (
$HOME/.netrc), so I get warnings with the new buildx version.Running
docker buildx bake(without arguments) is really convenient, I don't want to have to pass--allow=fs.read=/Users/milas/.netrcon every command. I understand the security angle, but UX-wise, this is a bit lacking.Can I:
buildkitd.tomlor similar?BUILDKIT_ALLOW_FS_READ=/Users/milas/.netrc)?All reactions