4 ms·
I used nspawn to get a system running in the most ridiculous way. A debian aarch64 vm on kvm starting a systemd-nspawn for an unpacked raspberry pi 3 iso. It
by letters90 2y ago
I used nspawn to get a system running in the most ridiculous way.
A debian aarch64 vm on kvm starting a systemd-nspawn for an unpacked raspberry pi 3 iso.
It works way too well judging by how ridiculous it was.
Still saved me a few days instead of setting things up myself.
I actually liked how easy it is to spin up nspawn as a systemd service
[Unit]
Description=Raspberry Image Machine
After=multi-user.target
[Service]
Type=simple
User=root
ExecStart=/usr/bin/systemd-nspawn -D /mnt/ /sbin/init
[Install]
WantedBy=multi-user.target
- Imustaskforhelp 2y agohmm this is very interesting. I am wondering though? Is there something like systemd-nspawn that doesn't require root?
- derobert 2y agoIt looks like systemd-nspawn is gaining rootless support, see https://github.com/systemd/systemd/issues/30239 https://github.com/systemd/systemd/issues/30239 Until then, I'm not sure if there is anything lightweight. If you don't need lightweight, there is Podman.
- Imustaskforhelp 2y agoPodman requires one time root for installation though. I am on a completely rootless client at one of my servers.
- tobwen 2y agoNope, you can compile/download and run it completely from unprivileged userspace.
- NekkoDroid 2y agoDo note that the current support is limited to signed disk images, while it was recently (still not in a release) gained the ability to use any directory that resides inside a signed disk image (instead of just the entire disk image).
- 1oooqooq 2y agoall containers require root. docker and the rootless nonsense is just root daemons and suid. ...would never have believed marketing lies would reach linux tools if anyone told me this before 2018.
- Imustaskforhelp 2y agoyou can theoretically run a virtual machine like libriscv5 which doesn't require root. or qemu doesn't require root as well. But qemu is blocked for my usecase. There is flatpak theoretically as well There is podman but it requires one time root.
- 1oooqooq 2y agoqemu is great but it's a VM, not a container.
- yjftsjthsd-h 2y agoLinux user namespaces can be used to create containers without having root access, see ex. https://unix.stackexchange.com/questions/66084/simulate-chroot-with-unshare https://unix.stackexchange.com/questions/66084/simulate-chro... There's also https://github.com/termux/proot-distro https://github.com/termux/proot-distro which may or may not count as containers depending on how you define the word but I think it does count
- 1oooqooq 2y agoyou can't detach your username from a process, nor the network ns... etc, etc, etc. yeah you can do some smaller fakechroot and maybe some bind mounts... if you call that a "container" good for you.
- yjftsjthsd-h 2y ago> you can't detach your username from a process, nor the network ns... etc, etc, etc. Sure looks like it works? $ unshare -i -n -p -u -T -r -f # ls # id gid=0(root) groups=0(root),65534(nogroup) # ip -br a lo DOWN > yeah you can do some smaller fakechroot and maybe some bind mounts... if you call that a "container" good for you. Why are you being condescending about what constitutes a container?
- vlowrian 2y agoIf file system level isolation is enough for you, take a loot at schroot (https://linux.die.net/man/1/schroot https://linux.die.net/man/1/schroot) which allows root-less chroot. You can use something like debootstrap to get a complete userland into a user controlled directory and use schroot to chroot into it without root level access.
- Imustaskforhelp 2y agothis is crazy , trying this out right now. But is there a way to also run OCI compatible directly on this as well?
- mst 2y agoYou could use docker export to sluro the container contents (see article for example)
- Imustaskforhelp 2y agoEDIT: it seems that for creating a chroot you still require root. I don't have root on that system and so I can't create a chroot , there is fakeroot but it doesn't work since it uses qemu on that locked system. Are there any other alternatives
- ttyprintk 2y agoFakeroot is good for the debootstrap step, and then schroot runs unprivileged.
- igor47 2y agofakeroot has nothing to do with qemu -- it simply uses LD preload to make commands think they're uid 0
- NekkoDroid 2y ago> it seems that for creating a chroot you still require root. You actually don't as long as you have user namespaces. One thing I am working on I use chroot (rather unshare --root=) to minimally sandbox a subprocess. At the beginning of the script I have this little snippet: if [ "$(id --user)" -ne 0 ]; then exec unshare --map-root-user --mount -- "$0" "$@" fi Though you can probably just do something roughtly as `unshare --map-root-user --root=<PATH>`.
- i_v 2y agoI used to use qemu-user-static to run ARM Linux distros like Buildroot, Yocto, and Raspbian on x88_64. It worked surprisingly well! Outside of some minor bugs here and there, it was perfect for local development, emulating an embedded system I was working on.
- vaylian 2y agoYou might want to look into .nspawn files instead. Then you can also manage your nspawn-containers with the machinectl command. See man 5 systemd.nspawn And many command like systemctl and journalctl accept the -M parameter, which allows you to query systemd units inside your nspawn-containers from the host. edit: The article actually explains all of these things in more detail.
- Vilian 2y agoWhy run the Debian VM? Just use nspawn directly