4 ms·
While rootless is a curious technical trick I don't understand why the implementation ever left someone's laptop, both file and networking performance are utter
by baobob 4y ago
While rootless is a curious technical trick I don't understand why the implementation ever left someone's laptop, both file and networking performance are utterly abysmal, which is completely at odds with one of the primary benefits of containers (near zero overhead).
- awoimbee 4y agoOn servers, yes, rootless doesn't make much sense. But on on my dev laptop, "sudo docker" is tiring and adding docker to the sudoers group is a big security hole (why does everyone seem to think that "docker run" giving root privileges is ok ?!).
- candiddevmike 4y agoYou should add yourself to the docker group...
- rcxdude 4y agowhich has the same effect, the docker group effectively has root access.
- Bayart 4y agosudo usermod -aG docker $USER
- prmoustache 4y agothis is not safer.
- moody5bundle 4y agothis is the same as: %wheel ALL=(ALL) NOPASSWD: ALL effectively disabling sudo completely.
- snorremd 4y agoThis indeed. The Docker team should not include the "adding your user to the docker group"-section in the install documentation. It is very unsafe and even though they link to a document on security implications I don't think all users will truly grasp the implications. Better to hide this feature and promote the rootless docker mode for local use. On servers you won't be adding any unprivileged user to the docker group in any case.
- mavhc 4y agooverlay2 or fuse-overlayfs?
- alduin32 4y agoWhat causes the file/networking performance degradation when running unprivileged containers ?
- AkihiroSuda 4y agoThe filesystem performance degradation was resolved in kernel 5.11 which added support for rootless overlayfs. The network performance is caused by slirp (usermode TCP/IP) but it is being resolved too : https://github.com/rootless-containers/bypass4netns https://github.com/rootless-containers/bypass4netns
- bogwog 4y agoThis is the first I've heard about serious performance overhead from going rootless. Do you have any links with more info about it? I haven't encountered any issues like this personally with rootless podman (although I'm not doing any large scale deployments).