MicroOS: Rootless podman?
from nico198x@europe.pub to selfhosted@lemmy.world on 02 May 03:42
https://europe.pub/post/390395

edit 2 Addendum

OK, big thanks to @oakcroissant@feddit.org for bringing this to attention here: europe.pub/post/390395/686949

that gets to the root (har har) of my confusion here. am i missing the point of MicroOS, or is it the devs who are wrong? šŸ˜†

their INTENTION with MicroOS is for us to just use root, which is contrary to how i’ve lived Linux basically forever.

Podmans rootless containers are AWESOME on Aeon, where you’re using it interactively and already have none root users… but that would just be adding unnecessary complications to MicroOS

MicroOS is designed to use with root, and there is no need to create a non root user for anything.

IF there was a need to create a non root user then the installer would create a non-root user

which is exactly what was tripping me up. why weren’t they facilitating rootless activity, and thus making me jump through hoops to get there.

answer: because it’s not needed, and not the intention.

MicroOS: run as root.


edit Answer

yes, MicroOS only generates a root user at install.

if you want to do rootless containers, you will need to create new, non-root users after.

useradd will NOT generate entries for subuid/subgid by default for the new SYSTEM users.

if the system user already exists, you will need to add them manually:

usermod --add-subuids 100000-165535 <yourusername>
usermod --add-subgids 100000-165535 <yourusername>

otherwise, you must use the -F flag with useradd to generate subids for new system users.

thanks all!


hey all! i need a little help here.

i’m just starting to get into self-hosting, and have chosen MicroOS and podman as my environment and tool.

would someone be able to clarify something for me?

I have a MicroOS install for containers, and it seems to only come with a root user. so if i use podman, won’t all my pods be rootful?

i try to make a new non-root user, but podman just keeps complaining about privileges when i run it under that user.

so how is this intended to work exactly?

thanks for any help!

#selfhosted

threaded - newest

Shimitar@downonthestreet.eu on 02 May 04:19 next collapse

I suggest you read some guides about podman and rootless containers.

Here is my experience albeit on a different Linux: wiki.gardiol.org/doku.php?id=gentoo%3Acontainers

nico198x@europe.pub on 02 May 04:24 collapse

i’ve been ass-deep in doc and guides for days, mate. can you just answer the question if you know the answer?

rootless podman should not be able to bind to port 80, for example. but i CAN do this on MicroOS. which is making me think that it’s running rootful. and if that’s happening because i’m working under the sole root user in MicroOS.

borax7385@lemmy.world on 02 May 04:35 next collapse

Which user do you use to run the podman command? Confirm with whoami

Note that the sysctl net.ipv4.ip_unprivileged_port_start can be used to allow non-root users to bind to ports <1024, this might be configured in MicroOS, I don’t know.

nico198x@europe.pub on 02 May 04:47 collapse

i’m definitely root, which is the sole default user on MicroOS for login, bash, etc.

it mostly strikes me as odd that MicroOS for containers would not have me setup a non-root user at install. trying to do it after install necessitates some hoop jumping to get podman to work correctly, which is making me wonder if MicroOS is really worth it at that point if it’s not ready to go after install.

driftWood@infosec.pub on 02 May 09:21 collapse

If you want extra users I believe you can create them in ignition file, so that way they get created when MicroOS is deployed.

Basically anything you want as part of ā€˜default’ setup has to be configured via ignition file.

nico198x@europe.pub on 02 May 09:33 collapse

yeah, i did try that, but that part failed for some reason. the rest of the Ignition file was ok.

Shimitar@downonthestreet.eu on 02 May 04:35 collapse

You can give podman rootless the power to open ports less than 1024. So no, it can still be rootless.

And yes, for being rootless you must have non root users as well…

So its probably root and not rootless

nico198x@europe.pub on 02 May 04:44 collapse

thank you for confirming my suspicion. i know one CAN give it that power, but i understand that it’s not the default.

ultimately, this is a question first about the MicroOS setup, and second podman functionality.

[deleted] on 02 May 04:40 next collapse

.

atzanteol@sh.itjust.works on 02 May 04:46 next collapse

i try to make a new non-root user, but podman just keeps complaining about privileges when i run it under that user.

If you’re asking for help about an error message, then provide the error message rather than describing it in vague terms. There are many privileges it could be complaining about.

nico198x@europe.pub on 02 May 04:53 collapse

not at this time, thank you. it’s more about confirming how MicroOS is functioning with a fresh install and where i need to head from there for rootless functionality. why this isn’t the default setup, i don’t know.

Sunny@slrpnk.net on 02 May 04:47 next collapse

I don’t run MicroOS myself so take this with a grain of salt. But this is usually how I do it, though there might be a better practice out there for this too.

Afaik, MicroOS by the sound of it, only ships with root by default, but rootless Podman should definitely be possible.

Normally, you need to set up user namespace mappings for your non-root user. Run these commands as root:

usermod --add-subuids 100000-165535 <yourusername>
usermod --add-subgids 100000-165535 <yourusername>

Then check they’re set up with:

grep <yourusername> /etc/subuid
grep <yourusername> /etc/subgid

This should give your regular user the ability to map container UIDs without needing root privileges. After that, Podman should work fine as your regular user.

Hope this helps a little šŸ‘

nico198x@europe.pub on 02 May 04:55 collapse

it does, thanks! i’m mostly really surprised that MicroOS hasn’t prepared all of this ahead of time for something that’s supposed to be a ā€œready for podman containersā€ install.

oakcroissant@feddit.org on 02 May 07:52 collapse

This is what the Aeon maintainer said about root vs rootless in MicroOS:

  1. Since MicroOS is immutable and not meant to be changed then there’s no problem running everything as root; root can’t even write to the immutable parts of the OS
  2. The main benefits for Podman on MicroOS are very many while not including rootless. No daemon to crash and make containers unmanageable. Nicer dependency chain making it easier to keep up to date on TW. Support for kubes… and many more

Source thread (Reddit)

Edit: spelling

nico198x@europe.pub on 02 May 09:35 collapse

that’s great, thanks for sharing! yeah, i love to hear their thoughts on this, since i’m new to ALL of this, immutables and containers. so i want to hear what their design intention is.

Getting6409@lemm.ee on 02 May 05:53 next collapse

I do this on the minimal Debian release which is essentially coming from the same place, you’re left to get things configured with a root user or maybe a privileged user after install. There’s a few things to tweak for rootless podman and it will vary based on the distro. The gist for me and Debian is:

  1. make an unprivileged account for running podman containers
  2. enable linger so i can use systemd with this account and the running of the containers
  3. allow lower ports for podman rootless in sysctl (for example, 80 if you’re running basic http services rootless), net.ipv4.ip_unprivileged_port_start=<start of lower range of ports rootless containers will use>
  4. run containers with the appropriate --userns flags. This can vary a lot depending on the container. Some maintainers are nice and ensure the internal uid/gid is something expected like 1000, sometimes not and you have to fire it up and figure out the app account name, uid/gid. An example I’ll put here is a podman run snippet for running jenkins (official image from cloudbees) rootless:

podman run --name jenkins --user jenkins --userns=keep-id:uid=1000,gid=1000 …

Again, that’s just Debian, never tried MicroOS, but if MicroOS isn’t doing anything special to accommodate rootless podman I imagine these steps are somewhat applicable. One issue I ran into was with an older version of Podman, whatever comes with Ubuntu 22: That version of podman requires you to set the namespace mappings; Debian 12’s version does not and the --userns=keep… flag just works.

nico198x@europe.pub on 02 May 06:00 collapse

fantastic, thank you!

yeah, when they said it was ā€œready for podmanā€ i, uh, expected a little more preconfig. XD

as an aside, re: point 3, port forwarding won’t work in firewalld? like , 80->8080, then 8080->container?

Getting6409@lemm.ee on 02 May 06:17 collapse

Honestly I’m not sure, or maybe I knew but forgot. Since working out my needs I wrote it to ansible and never looked back. Worth trying the more secure way for sure.

someacnt@sh.itjust.works on 02 May 21:03 collapse

While this would not answer your question, but according to podman maintainers, rootful podman with userns=auto enjoys nearly as much security benefits as rootless. (As always, there are nuances to this)

Check out github.com/containers/podman/discussions/13728

Maybe you could consider running rootful podman, especially if the OS is immutable.

InnerScientist@lemmy.world on 03 May 00:12 next collapse

Tldr:

Rootful podman with podman run --userns=auto is more secure than one rootless host user running many pods, because those pods could (theoretically) attack each other.
though you still have the possibility of an exploit in the image pull

Rootless podman running one pod (as in service including database and so on) per host user with different subuid Ranges is the most secure, but you have to actually set that up which can be a lot of work depending on distribution.

nico198x@europe.pub on 03 May 01:32 collapse

thanks, very helpful! your comment is definitely relevant, and i hope this topic will help others in the future who may be confused about best practice w/ MicroOS.

for what it’s worth, i did end up running Rootful!