You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Reference [subuid](http://man7.org/linux/man-pages/man5/subuid.5.html) and [subgid](http://man7.org/linux/man-pages/man5/subgid.5.html) man pages for more detail.
497
497
498
-
### 20) Passed-in device can't be accessed in rootless container
498
+
### 20) Passed-in devices or files can't be accessed in rootless container
499
499
500
-
As a non-root user you have group access rights to a device that you want to
501
-
pass into a rootless container with `--device=...`.
500
+
As a non-root user you have group access rights to a device or files that you
501
+
want to pass into a rootless container with `--device=...` or `--volume=...`
502
502
503
503
#### Symptom
504
504
@@ -507,9 +507,9 @@ Any access inside the container is rejected with "Permission denied".
507
507
#### Solution
508
508
509
509
The runtime uses `setgroups(2)` hence the process looses all additional groups
510
-
the non-root user has. If you use the `crun` runtime, 0.10.4 or newer,
511
-
then you can enable a workaround by adding `--annotation io.crun.keep_original_groups=1`
512
-
to the `podman` command line.
510
+
the non-root user has. Use the `--group-add keep-groups` flag to pass the
511
+
user's supplementary group access into the container. Currently only available
512
+
with the `crun` OCI runtime.
513
513
514
514
### 21) A rootless container running in detached mode is closed at logout
0 commit comments