Install nested rootless Podman and expose launcher security modes - #474
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
--podman-security=off|nested|unconfined|privileged(orDEV_PODMAN_SECURITY) controls outer confinement.DEV_PODMAN_PERSIST=1gives Podman a per-project volume independent of Docker, home, and workspace.Usage
run-dev-docker.sh(orrun-dev-podman.sh) usesnestedby default. On hosts where AppArmor blocks nested user namespaces, use--podman-security=unconfined;privilegedis a broader fallback.offretains the ordinary outer security profile, but nested Podman may fail. The default mode requires/dev/fuseon the host; changing flags does not update already-created containers. Checkpodman infoandpodman run --rm docker.io/library/alpine:latest trueinside a newly built sandbox to verify actual runtime support.Testing / review blockers
sh -n,test-home-volume.sh, image-build tests, live rootless Docker/Podman smoke tests, and the chezmoi apply check have not run here; the container runtime has no/dev/fuse, and GitHub/network access from its shell is unavailable.containers/dev-dotfiles-debian/README.mdhas not yet been updated; keep this PR draft until it documents the installed Podman engine, the launcher flag, host FUSE/namespace prerequisite, optional storage persistence, security consequences, migration and smoke test. Check Debian stable package availability and rootless user-namespace support in the built image before marking ready.