3 ms·
No mention of user namespaces whatsoever, which is the primary security isolation mechanism for containers on linux. This is what enables "rootless" mode. Of co
by epr 2y ago
No mention of user namespaces whatsoever, which is the primary security isolation mechanism for containers on linux. This is what enables "rootless" mode. Of course, this is from 2017, but user namespaces were released with linux 3.8 in February 2013.
Docker particularly has always required extra work to run in rootless mode because it was released soon after in March 2013, and for whatever reason it hasn't been a priority to rework the codebase to make that the default. I switched to podman for exactly this reason as my go-to oci implementation and haven't looked back.
The linux kernel features that enable various forms of isolation all require root privileges (CAP_SYS_ADMIN). Once user namespaces were a thing, that allowed you to use user namespaces to get around the root requirements for all the other isolation namespaces.
All of the below still require CAP_SYS_ADMIN:
CLONE_NEWCGROUP: cgroup namespace, for resource control (mem/cpu/block io/devices/network bandwith)
CLONE_NEWIPC: ipc namespace for sysv ipc objects and message queues
CLONE_NEWNET: network namespace, for isolated virtual networking
CLONE_NEWNS: mount namespace, for isolated mounting (filesystems, etc.)
CLONE_NEWPID: pid namespace, for isolated view of running processes
CLONE_NEWUTS: unix timesharing system namespace, for isolation of hostname and domain name
see: https://man7.org/linux/man-pages/man2/clone.2.html https://man7.org/linux/man-pages/man2/clone.2.html
- ledgerdev 2y agoThanks for the suggestion, I was unaware of podman and will be trying it out because root has always bothered me.
- angra_mainyu 2y agoPodman is fantastic! It can also handle kubernetes and generate systemd units for containers.
- ledgerdev 2y ago> generate systemd units for containers Oh man that is something I've been wanting as well.
- sureglymop 2y agoNowadays it is fairly straightforward to set up docker in rootless mode.
- epr 2y agoExactly, "set up". Many people (not all) don't want to fiddle with things, they just want it to work out of the box. The importance of secure defaults can't be overstated, especially when there are virtually no downsides.
- DEADMINCE 2y agoIt's more work to switch to podman than it is to just configure docker to run rootless.