diff --git a/roles/container-engine/containerd/defaults/main.yml b/roles/container-engine/containerd/defaults/main.yml index 291e96e34..b7b821fab 100644 --- a/roles/container-engine/containerd/defaults/main.yml +++ b/roles/container-engine/containerd/defaults/main.yml @@ -61,6 +61,8 @@ containerd_registries_mirrors: containerd_max_container_log_line_size: -1 +containerd_ignore_image_defined_volumes: false + # If enabled it will allow non root users to use port numbers <1024 containerd_enable_unprivileged_ports: false # If enabled it will allow non root users to use icmp sockets diff --git a/roles/container-engine/containerd/templates/config.toml.j2 b/roles/container-engine/containerd/templates/config.toml.j2 index 23e2d7b5b..d41319690 100644 --- a/roles/container-engine/containerd/templates/config.toml.j2 +++ b/roles/container-engine/containerd/templates/config.toml.j2 @@ -20,6 +20,7 @@ oom_score = {{ containerd_oom_score }} [plugins] [plugins."io.containerd.grpc.v1.cri"] + ignore_image_defined_volumes = {{ containerd_ignore_image_defined_volumes }} sandbox_image = "{{ pod_infra_image_repo }}:{{ pod_infra_image_tag }}" max_container_log_line_size = {{ containerd_max_container_log_line_size }} enable_unprivileged_ports = {{ containerd_enable_unprivileged_ports | lower }}