I have published a couple of videos that cover an overview of rootless containers through practical demonstration. If you are curious about terms like "rootless containers" or "running a container rootless as non-root," these videos will explain what they are and the benefits that these features provide.
The first video, Overview of Rootless Podman: Part 1—Understanding Root Inside and Outside a Container, I cover the four different options when running containers with podman:
- Running podman as root, with processes in the container running as root
- Running podman as root, with processes in the container running as non-root
- Running podman as an unprivileged user (rootless), with processes in the container running as root
- Running podman as an unprivileged user (rootless), with processes in the container running as non-root (also known as rootless as a non-root user)
Each of these options is explained, and a demonstration of each of them is also shown in the first video.
In the second video, Overview of Rootless Podman: Part 2—How User Namespaces Work in Rootless Containers, I dive deep into how user namespaces work in rootless podman, and demo the following topics:
- Running a container with rootless podman
- View user namespaces with the lsns command
- Review the /etc/subuid file, which defines subordinate UID ranges
- Review the /proc/<pid>/uid_map file, which shows the UID map for a process
- Calculate the UID number that a process will use on the host
- Use the podman top command to view the mapping of users between the container and the host
- Use the podman unshare command to run a command within a container's user namespace
These videos should provide you a better understanding of how user namespaces work and the various options that are available when running containers with podman.
[ Getting started with containers? Check out this free course. Deploying containerized applications: A technical overview. ]
執筆者紹介
Brian Smith is a product manager at Red Hat focused on RHEL automation and management. He has been at Red Hat since 2018, previously working with public sector customers as a technical account manager (TAM).
類似検索
Ford's keyless strategy for managing 200+ Red Hat OpenShift clusters
F5 BIG-IP Virtual Edition is now validated for Red Hat OpenShift Virtualization
Can Kubernetes Help People Find Love? | Compiler
Scaling For Complexity With Container Adoption | Code Comments
チャンネル別に見る
自動化
テクノロジー、チームおよび環境に関する IT 自動化の最新情報
AI (人工知能)
お客様が AI ワークロードをどこでも自由に実行することを可能にするプラットフォームについてのアップデート
オープン・ハイブリッドクラウド
ハイブリッドクラウドで柔軟に未来を築く方法をご確認ください。
セキュリティ
環境やテクノロジー全体に及ぶリスクを軽減する方法に関する最新情報
エッジコンピューティング
エッジでの運用を単純化するプラットフォームのアップデート
インフラストラクチャ
世界有数のエンタープライズ向け Linux プラットフォームの最新情報
アプリケーション
アプリケーションの最も困難な課題に対する Red Hat ソリューションの詳細
仮想化
オンプレミスまたは複数クラウドでのワークロードに対応するエンタープライズ仮想化の将来についてご覧ください