Mounting a group-writable folder into a systemd controlled quadlet for an unprivileged user #29710
|
i'm having difficulties to set up a container with a mounted volume, my eventual goal is to run a service that:
to achieve that i define a
so, i'd appreciate hints in these regards:
#!/bin/sh
set -ex
CONTAINER_FILE=/root/Containerfile
QUEUE_FOLDER=/var/lib/queue
SERVICE_NAME=queue-folder-test
STAFF_GID=$(getent group staff | cut -d ':' -f 3)
mkdir -p $QUEUE_FOLDER
chown root:staff $QUEUE_FOLDER
chmod u=rwx,g=rwxs,o= $QUEUE_FOLDER
cat > $CONTAINER_FILE << EOF
FROM alpine
RUN addgroup -g 1000 container-staff \
&& adduser -G container-staff -D -H container-user
USER container-user
CMD ["/bin/sh", "-c", "touch", "/container-queue/test"]
EOF
podman build --tag "$SERVICE_NAME" --file $CONTAINER_FILE .
cat > /etc/containers/systemd/$SERVICE_NAME.container << EOF
[Container]
ContainerName=$SERVICE_NAME
Image=$SERVICE_NAME
GIDMap=g1000:$STAFF_GID
Volume=$QUEUE_FOLDER:/container-queue:z
[Install]
WantedBy=default.target
EOF
systemctl daemon-reload
systemctl enable $SERVICE_NAME
systemctl start $SERVICE_NAME |
Replies: 2 comments
|
Your mapping never maps GID 0, and that is what the container dies on. With podman 5.4.2 the same mapping gets rejected before crun is involved, with a message that names the problem: The write to The The bigger thing is that you do not need the namespace here. Your unit is in [Container]
User=1000
Group=50
Volume=/var/lib/queue:/container-queue:z50 being whatever I set a directory up the way your script does, If you want the namespace anyway, it has to map 0 as well. This works on the same directory: GIDMap=0:0:1
GIDMap=1000:50:1
UIDMap=0:0:1
UIDMap=1000:1000:1
User=1000
Group=1000One thing that is waiting for you once the mapping is sorted: And if this unit is ever meant to run under a user's own systemd instance rather than root's, that is a rootless quadlet, the namespace is back, and the host directory then has to be reachable through that user's subuid range instead of through group membership. |
|
thank you very much! your elaboration really helped me a lot to get my grip around this. |
Your mapping never maps GID 0, and that is what the container dies on. With podman 5.4.2 the same mapping gets rejected before crun is involved, with a message that names the problem:
The write to
ping_group_rangeis the same problem further down. podman sets that sysctl inside the container's namespace, the write is rejected because the ids involved are not mapped, and crun can only report the write that failed. So I would not file anything against crun. The message quoted above comes from pod…