Fix description of :Z to talk about pods

Fixes: 23329

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
This commit is contained in:
Daniel J Walsh
2024-08-19 09:44:40 -04:00
parent 7899358ec9
commit d5cd388729

View File

@@ -81,7 +81,9 @@ objects on the shared volumes. The **z** option tells Podman that two or more
content with a shared content label. Shared volume labels allow all containers
to read/write content. The **Z** option tells Podman to label the content with
a private unshared label Only the current <<container|pod>> can use a private
volume. Relabeling walks the file system under the volume and changes the label
volume. Note: all containers within a `pod` share the same SELinux label. This
means all containers within said pod can read/write volumes create with the
`:Z`. Relabeling walks the file system under the volume and changes the label
on each file, if the volume has thousands of inodes, this process takes a
long time, delaying the start of the <<container|pod>>. If the volume
was previously relabeled with the `z` option, Podman is optimized to not relabel