Overview of Rootless Podman: Part 1 - Understanding Root Inside and Outside a Container
HTML-код
- Опубликовано: 7 окт 2024
- Follow along with Red Hat's Principal Technical Account Manager Brian Smith as he gives an overview of rootless Podman.
Part 2 can be found here: • Overview of Rootless P...
For more information, please see these links:
www.redhat.com...
access.redhat....
by far, the most concise and easily understood primer to outside vs. inside user mappings.
This is so cool thank you for the split screen comparisons!
Clear and concise, well done
This is perfection
5:13 : putting any char of the grep string in brackets [] makes the "grep -v grep" unnecessary
ps -ef|grep "/usr/lib/systemd/systemd rhgb" -> grep process shows up in the result
ps -ef|grep "[/]usr/lib/systemd/systemd rhgb" -> grep process does not show up in the result
ps -ef|grep "/usr/lib/sys[t]emd/systemd rhgb" -> grep process does not show up in the result
clearedthe confusion. tnx
Very well explained. Thanks..
In scenario #4, if a container were to share a volume with the host and a file were created in that shared volume, the host would have a permissions denied on that file. What would be the process to get around that? .. thanks in advance.
good question... I'm also struggling with this. have to use root to even ls
@@rahilarious In my case this was a SELinux problem. You need to add :Z to the volume mapping parameter to set the SELinux labels. Then everything works as expected.
I had to do two things: match the UID and GID of the host user (PUID and PGID lines in the compose file) and secondly append :Z to the volume to indicate the volume is shared in order to make SELinux happy (on Rocky 9.2)
I went from docker on rhel to podman. worst decision of the year
Do you have a guide on running this on Openshift 4.11?
Between 01:10 and 04:40 there are diff scenarios but shell prompt stays the same.
# whoami
sync
and not:
$ whoami
sync
Am I missing something?
Thanks
The prompt symbol is just a convention.
Rootless user when try to initialize systemctl from the ubi images get DBus connection failed. Is that by design?
I wanted to like Podman, but all this rootless/rootful stuff is black magic. Unnecessarily complicated. I't so easy to get lost with this stuff. I'll stick with the simplicity of Docker. It just works