4 ms·
In that sense docker is also "rootless". Won't be surprising if Canonical does not understand the words they use. EDIT: actually I find no claims that LXD/LXC
by jaekash 6y ago
In that sense docker is also "rootless". Won't be surprising if Canonical does not understand the words they use.
EDIT: actually I find no claims that LXD/LXC supports rootless containers, I think the person claiming it does just don't understand it, would like to see a citation for it.
- markshuttle 6y agoThat's because by default ALL containers in LXD are unprivileged. They use the term unprivileged because the term rootless wasn't around that far back ;) LXD uses various mechanisms to map the uid-in-container to a uid-on-host. So root-in-container is not root on host. There are a lot of details to work through to make that work neatly, and there is still kernel work being done to map this nicely into the filesystem, but it works, and it's the default, and the FAQ recommends strongly not to grant real-root to your containers, for a good reason.
- hardwaresofton 6y agoGreat summary -- for anyone interested in the kernel side, there's a talk from 2019 called "A year of Container Kernel Work Past, Present, and Future of Container Kernel Features"[0] which goes into the timeline and future work being done. I'm not sure where it is today but it's a good watch. [0]: https://www.youtube.com/watch?v=TnArHYRYT3U https://www.youtube.com/watch?v=TnArHYRYT3U