How to audit container process syscall?

Viewed 13

I'm want to using auditd to do some audit for container process, but it looks like there is on way to discriminate host process and container process.

I have tried two ways.

First way using never to ignore host process like below, because I never mount /usr/bin dir into container:

#!/bin/bash

auditctl -D
auditctl -a exit,never -S all -F dir=/usr/bin  -k key_exclude
auditctl -a exit,always -S exit_group  -k key_match
auditctl -l

but it not work, I can still find the key_match for /usr/bin/xxx.

Second way, I want to watch shim and its child process, because all the container process is child-process of shim, the ps tree like below

   885 ? -1 Sl       0   0:00 /usr/bin/containerd-shim-runc-v2 -namespace moby -id c78997f3eeeb1e2fc712155435c7d361e1c759f769c589d335d397a9ed431ea4 -addr
310170 ? -1 Ss       0   0:00  \_ /bin/s6-svscan /etc/s6
310170 ? -1 S        0   0:00      \_ s6-supervise gitea
310221 ? -1 Ssl   1000   0:17      |   \_ /usr/local/bin/gitea web
310170 ? -1 S        0   0:00      \_ s6-supervise openssh
310222 ? -1 Ss       0   0:00          \_ sshd: /usr/sbin/sshd -D -e [listener] 0 of 10-100 startups

but I'm not sure how to watch shim and it's child-process.

0 Answers
Related