-
Notifications
You must be signed in to change notification settings - Fork 2.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Is rootless container nested in rootless container possible? #10705
Comments
Another Podman in Podman, @rhatdan
…On Thu, Jun 17, 2021 at 07:36 Jan Palus ***@***.***> wrote:
Actually not even nested container, but just podman import and podman push
inside rootless container. Every podman command invoked inside container
results in:
Error: cannot setup namespace using newuidmap: exit status 1
If strace is to be believed that's likely because of:
capset({version=_LINUX_CAPABILITY_VERSION_3, pid=0}, {effective=1<<CAP_SETUID, permitted=1<<CAP_SETUID, inheritable=0}) = -1 EPERM (Operation not permitted)
newuidmap has proper file capabilities.
Tried also with seccomp=unconfined but still same result. Anything I
might be missing?
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
<#10705>, or unsubscribe
<https://github.com/notifications/unsubscribe-auth/AB3AOCHIL3AE7TRXCJJUSR3TTHM3RANCNFSM463PN4GA>
.
|
Try using quay.io/podman/stable image.
|
@rhatdan indeed if initial container is started like this then it works fine. |
Could you give me a reproducer? |
I'm on ARM machine right now hence base image is ARM, but swapping image to your architecture should do:
|
We have just published https://www.redhat.com/sysadmin/podman-inside-container Please read these and see if they help solve your problem. Reopen if you need more information. |
Actually not even nested container, but just
podman import
andpodman push
inside rootless container. Every podman command invoked inside container results in:If strace is to be believed that's likely because of:
newuidmap
has proper file capabilities.Tried also with
seccomp=unconfined
but still same result. Anything I might be missing?The text was updated successfully, but these errors were encountered: