Skip to content

Install nested rootless Podman and expose launcher security modes - #474

Merged
arran4 merged 7 commits into
mainfrom
feat/nested-podman-with-launcher-security
Sep 24, 2026
Merged

arran4 merged 7 commits into
mainfrom
feat/nested-podman-with-launcher-security

Conversation

@arran4

@arran4 arran4 commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Summary

  • Install the Debian Podman CLI/engine, uidmap, FUSE-overlay storage and rootless networking dependencies inside the canonical development image. Allocate in-container subordinate UIDs/GIDs and a private rootless store rather than depending on a host runtime socket.
  • Both Docker and Podman launchers default to nested-Podman-compatible FUSE/seccomp/SELinux settings for new containers. --podman-security=off|nested|unconfined|privileged (or DEV_PODMAN_SECURITY) controls outer confinement. DEV_PODMAN_PERSIST=1 gives Podman a per-project volume independent of Docker, home, and workspace.
  • Initialize the private runtime directory and optional storage volume mount root at startup, preserving existing Docker-in-Docker behaviour and stopped-container layout.

Usage

run-dev-docker.sh (or run-dev-podman.sh) uses nested by default. On hosts where AppArmor blocks nested user namespaces, use --podman-security=unconfined; privileged is a broader fallback. off retains the ordinary outer security profile, but nested Podman may fail. The default mode requires /dev/fuse on the host; changing flags does not update already-created containers. Check podman info and podman run --rm docker.io/library/alpine:latest true inside a newly built sandbox to verify actual runtime support.

Testing / review blockers

  • Launcher tests were expanded to cover flag precedence, invalid modes, privileged mode and the independent storage mount. They have not been executed in this tool environment.
  • sh -n, test-home-volume.sh, image-build tests, live rootless Docker/Podman smoke tests, and the chezmoi apply check have not run here; the container runtime has no /dev/fuse, and GitHub/network access from its shell is unavailable.
  • Documentation blocker: the canonical containers/dev-dotfiles-debian/README.md has not yet been updated; keep this PR draft until it documents the installed Podman engine, the launcher flag, host FUSE/namespace prerequisite, optional storage persistence, security consequences, migration and smoke test. Check Debian stable package availability and rootless user-namespace support in the built image before marking ready.
  • Do not merge until a smoke test confirms that the chosen outer mode actually runs inner Podman on the target host and the README is synchronized.

@arran4
arran4 marked this pull request as ready for review September 24, 2026 06:23
@arran4
arran4 merged commit 7871692 into main Sep 24, 2026
11 of 12 checks passed
@arran4
arran4 deleted the feat/nested-podman-with-launcher-security branch September 24, 2026 06:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant