3 ms·
I’ve recently been using proot [1] as a way to have a fully controlled rootfs for jobs on a HPC cluster/grid service where I am a very regular unprivileged user
by svd4anything 7y ago
I’ve recently been using proot [1] as a way to have a fully controlled rootfs for jobs on a HPC cluster/grid service where I am a very regular unprivileged user.
Is it theoretically possible I could run an entire linux kernel instead with this? Is there any setup on the host system that is required which needs administrative privileges?
[1] https://proot-me.github.io/ https://proot-me.github.io/
- CameronNemo 7y agoI do not have much info on UML, but you may be interested in https://rootlesscontaine.rs/ https://rootlesscontaine.rs/
- gnufx 7y agoUnless you're interested in OCI (?) containers, you're probably better off with straight proot, or charlecloud if you're allowed user namespaces. https://github.com/hpc/charliecloud https://github.com/hpc/charliecloud
- gnufx 7y agoYes, Proot is useful, but limited. It will be somewhat slow in some cases and not do the right thing in others, like interpret shebangs as expected, as namespaces will. In most cases you can run HPC stuff by installing packages under proot and setting paths in the environment appropriately to use the resulting root. (I don't know if that's the case here, or if it means running under proot.) No, you certainly can't run your own kernel that way.
- ktpsns 7y agoThe HPC usage scenario is exactly the reason why I played with UML a few years ago. Many HPC clusters nowadays completely lock down the network and only allow in/outbound SSH connections to whitelisted IP networks. On the other hand, users are only given an unpriviledged account. Typically, users set up proxies on a per-application level (i.e. for git, svn, to sync their codes with the outer world). I found this very frustrating and wanted to use any usual Linux command line tools. My idea was a UML based virtual machine (ie. running a Linux distribution within UML) and have it connected to the outer world by tunneling a single slirp and VDE connection. VDE is quite amazing because it marries unix pipes with ethernet-level networking. It even allows to run ethernet switches as processes and all that. My codes based on https://github.com/jpetazzo/sekexe https://github.com/jpetazzo/sekexe Turned out: It basically worked, but it was a bit painful to setup and to manage.
- svd4anything 7y agoThat is very helpful to know it has been done, thank you. I need to try UML out it seems. The SMP issue and any overhead are other big questions.
- gnufx 7y agoI'd have thought it would be relatively unusual not to be able to use HTTP into a cluster login node, but I'm puzzled why you can't "sync code" with ssh otherwise. If you're prevented from doing things you need to work, it sounds like an institutional politics problem; subverting controls is likely to cause more friction as well as presumably wasting resources due to inefficiency.
- zoobab 7y agoUdocker also use Proot: https://github.com/indigo-dc/udocker https://github.com/indigo-dc/udocker I used it on a server where I was not root to be able to launch docker containers.