_placement
_placement
¶
Where this host runs a container's supervisor — and so, where its readers live.
One fact decides it, and the OCI hook reads the same fact through the
same predicate: a per-user systemd manager that answers. With one, the
supervisor is a transient user unit in the operator's own namespaces,
and the kernel user keyring it reads is the operator's. Without one, it
is a daemon inside the container runtime's user namespace, where that
keyring is an empty stranger and only a path can carry the passphrase
across. The cache tier follows the placement for exactly that reason
(see session_cache).
__all__ = ['SupervisorPlacement', 'supervisor_placement']
module-attribute
¶
supervisor_placement()
¶
Where a supervisor started from this process would run.