20 ms·
Just to make sure: "rootless" is really misleading. As far as I researched, podman either relies on suid binaries or privileged capabilities or both to do its m
by anticristi 4y ago
Just to make sure: "rootless" is really misleading. As far as I researched, podman either relies on suid binaries or privileged capabilities or both to do its magic. You might as well call it "capabilitiesful podman driver".
- mishafb 4y agoYou do need an suid binary to e.g. set a new user id map, since this requires comparing the user id range owned by you to what you're mapping, but you only do it once and it's a simple, secure operation.
- encryptluks2 4y agoI don't think it is misleading. Just because you need root privileges to enable "rootless" doesn't mean it isn't rootless once configured.
- RandomBK 4y agoIt's somewhere in between. You definitely need to enable features that are normally out-of-reach of regular users (i.e. user namespaces, network namespace, unprivileged ping, etc.) However it's still a far cry from full root access, and arguably a smaller surface area than regular run-everything-as-root mode.
- wronglyprepaid 4y ago> podman either relies on suid binaries I'm fairly sure this is only the case on older systems, if your system is up to date then podman should not rely on suid binaries.
- moody5bundle 4y agoMaybe you should include this into your "research": - https://opensource.com/article/19/2/how-does-rootless-podman-work https://opensource.com/article/19/2/how-does-rootless-podman... - https://github.com/containers/podman/blob/main/docs/tutorials/rootless_tutorial.md https://github.com/containers/podman/blob/main/docs/tutorial... TL;DR cgroup V2 support Installing Podman Install slirp4netns Ensure fuse-overlayfs is installed
- znpy 4y agoyou can run containers without root, suid bits or special capabilities with podman. of course, withouth any of that your containers will be able to do very little (eg: no networking).
- AkihiroSuda 4y agoSlirp networking does not need any suid bit or special capability.