I'm want to using auditd to do some audit for container process, but it looks like there is on way to discriminate host process and container process.
I have tried two ways.
First way using never to ignore host process like below, because I never mount /usr/bin dir into container:
#!/bin/bash
auditctl -D
auditctl -a exit,never -S all -F dir=/usr/bin -k key_exclude
auditctl -a exit,always -S exit_group -k key_match
auditctl -l
but it not work, I can still find the key_match for /usr/bin/xxx.
Second way, I want to watch shim and its child process, because all the container process is child-process of shim, the ps tree like below
885 ? -1 Sl 0 0:00 /usr/bin/containerd-shim-runc-v2 -namespace moby -id c78997f3eeeb1e2fc712155435c7d361e1c759f769c589d335d397a9ed431ea4 -addr
310170 ? -1 Ss 0 0:00 \_ /bin/s6-svscan /etc/s6
310170 ? -1 S 0 0:00 \_ s6-supervise gitea
310221 ? -1 Ssl 1000 0:17 | \_ /usr/local/bin/gitea web
310170 ? -1 S 0 0:00 \_ s6-supervise openssh
310222 ? -1 Ss 0 0:00 \_ sshd: /usr/sbin/sshd -D -e [listener] 0 of 10-100 startups
but I'm not sure how to watch shim and it's child-process.