I have published a couple of videos that cover an overview of rootless containers through practical demonstration. If you are curious about terms like "rootless containers" or "running a container rootless as non-root," these videos will explain what they are and the benefits that these features provide.

The first video, Overview of Rootless Podman: Part 1โ€”Understanding Root Inside and Outside a Container, I cover the four different options when running containers with podman:

  • Running podman as root, with processes in the container running as root
  • Running podman as root, with processes in the container running as non-root
  • Running podman as an unprivileged user (rootless), with processes in the container running as root
  • Running podman as an unprivileged user (rootless), with processes in the container running as non-root (also known as rootless as a non-root user)

Each of these options is explained, and a demonstration of each of them is also shown in the first video.

In the second video, Overview of Rootless Podman: Part 2โ€”How User Namespaces Work in Rootless Containers, I dive deep into how user namespaces work in rootless podman, and demo the following topics:

  • Running a container with rootless podman
  • View user namespaces with the lsns command
  • Review the /etc/subuid file, which defines subordinate UID ranges
  • Review the /proc/<pid>/uid_map file, which shows the UID map for a process
  • Calculate the UID number that a process will use on the host
  • Use the podman top command to view the mapping of users between the container and the host
  • Use the podman unshare command to run a command within a container's user namespace

These videos should provide you a better understanding of how user namespaces work and the various options that are available when running containers with podman.

[ Getting started with containers? Check out this free course. Deploying containerized applications: A technical overview. ]


์ €์ž ์†Œ๊ฐœ

Brian Smith is a product manager at Red Hat focused on RHEL automation and management.  He has been at Red Hat since 2018, previously working with public sector customers as a technical account manager (TAM).  

UI_Icon-Red_Hat-Close-A-Black-RGB

์ฑ„๋„๋ณ„ ๊ฒ€์ƒ‰

automation icon

์˜คํ† ๋ฉ”์ด์…˜

๊ธฐ์ˆ , ํŒ€, ์ธํ”„๋ผ๋ฅผ ์œ„ํ•œ IT ์ž๋™ํ™” ์ตœ์‹  ๋™ํ–ฅ

AI icon

์ธ๊ณต์ง€๋Šฅ

๊ณ ๊ฐ์ด ์–ด๋””์„œ๋‚˜ AI ์›Œํฌ๋กœ๋“œ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›ํ•˜๋Š” ํ”Œ๋žซํผ ์—…๋ฐ์ดํŠธ

open hybrid cloud icon

์˜คํ”ˆ ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํด๋ผ์šฐ๋“œ

ํ•˜์ด๋ธŒ๋ฆฌ๋“œ ํด๋ผ์šฐ๋“œ๋กœ ๋”์šฑ ์œ ์—ฐํ•œ ๋ฏธ๋ž˜๋ฅผ ๊ตฌ์ถ•ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด์„ธ์š”

security icon

๋ณด์•ˆ

ํ™˜๊ฒฝ๊ณผ ๊ธฐ์ˆ  ์ „๋ฐ˜์— ๊ฑธ์ณ ๋ฆฌ์Šคํฌ๋ฅผ ๊ฐ์†Œํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์ตœ์‹  ์ •๋ณด

edge icon

์—ฃ์ง€ ์ปดํ“จํŒ…

์—ฃ์ง€์—์„œ์˜ ์šด์˜์„ ๋‹จ์ˆœํ™”ํ•˜๋Š” ํ”Œ๋žซํผ ์—…๋ฐ์ดํŠธ

Infrastructure icon

์ธํ”„๋ผ

์„ธ๊ณ„์ ์œผ๋กœ ์ธ์ •๋ฐ›์€ ๊ธฐ์—…์šฉ Linux ํ”Œ๋žซํผ์— ๋Œ€ํ•œ ์ตœ์‹  ์ •๋ณด

application development icon

์• ํ”Œ๋ฆฌ์ผ€์ด์…˜

๋ณต์žกํ•œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•œ ์†”๋ฃจ์…˜ ๋” ๋ณด๊ธฐ

Virtualization icon

๊ฐ€์ƒํ™”

์˜จํ”„๋ ˆ๋ฏธ์Šค์™€ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ ์›Œํฌ๋กœ๋“œ๋ฅผ ์œ ์—ฐํ•˜๊ฒŒ ์šด์˜ํ•˜๊ธฐ ์œ„ํ•œ ์—”ํ„ฐํ”„๋ผ์ด์ฆˆ ๊ฐ€์ƒํ™”์˜ ๋ฏธ๋ž˜