Skip to content

Commit

Permalink
docs: add Linux capabilities config for pyroscope.java
Browse files Browse the repository at this point in the history
  • Loading branch information
marcsanmi committed Oct 4, 2024
1 parent 8d97a39 commit 4c1606c
Showing 1 changed file with 22 additions and 0 deletions.
22 changes: 22 additions & 0 deletions docs/sources/reference/components/pyroscope/pyroscope.java.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,28 @@ When you use `pyroscope.java` to profile Java applications, you can configure th

For more details, refer to [Restrictions/Limitations](https://github.com/async-profiler/async-profiler?tab=readme-ov-file#restrictionslimitations) in the async-profiler documentation.

## Additional Configuration for Linux Capabilities

If your Kubernetes environment has Linux capabilities enabled, configure the following in your Helm values to ensure `pyroscope.java` functions properly:

```yaml
alloy:
securityContext:
runAsUser: 0
runAsNonRoot: false
capabilities:
add:
- PERFMON
- SYS_PTRACE
- SYS_RESOURCE
- SYS_ADMIN
```
These capabilities enable Alloy to access performance monitoring subsystems, trace processes, override resource limits, and perform necessary system administration tasks for profiling.
{{< admonition type="note" >}}
Adjust capabilities based on your specific security requirements and environment, following the principle of least privilege. Note that capability behavior depends on Container Runtime Interface (CRI) settings. For example, in Docker, non-whitelisted capabilities are dropped by default.
{{< /admonition >}}
## Arguments
The following arguments are supported:
Expand Down

0 comments on commit 4c1606c

Please sign in to comment.