3 ms·
The parent comment is still talking about rootless podman (and really just user namespaces). Root in the container is absolutely mapped to the user executing po
by gnfurlong 4y ago
The parent comment is still talking about rootless podman (and really just user namespaces). Root in the container is absolutely mapped to the user executing podman outside the container.
If it mapped to root outside the container, you could just use podman to create setuid scripts owned by root for very trivial privelege escalation.
- RyEgswuCsn 4y agoYes I think you are right --- I was mistaken. Docker without the rootless operate in the way I described.