* Isar-based projects using kas-container and podman-rootless
@ 2023-02-28 5:58 Krishnakar, Srikanth
2023-02-28 6:15 ` Jan Kiszka
0 siblings, 1 reply; 2+ messages in thread
From: Krishnakar, Srikanth @ 2023-02-28 5:58 UTC (permalink / raw)
To: isar-users; +Cc: kas-devel
[-- Attachment #1: Type: text/plain, Size: 246 bytes --]
Hello,
Can we build Isar-based projects using kas-container+podman but without any privilege escalations of any sorts on the host (container may do whatever it needs to as long as it is not running with --privileged) ?
Thanks,
Srikanth
[-- Attachment #2: Type: text/html, Size: 2114 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Isar-based projects using kas-container and podman-rootless
2023-02-28 5:58 Isar-based projects using kas-container and podman-rootless Krishnakar, Srikanth
@ 2023-02-28 6:15 ` Jan Kiszka
0 siblings, 0 replies; 2+ messages in thread
From: Jan Kiszka @ 2023-02-28 6:15 UTC (permalink / raw)
To: Krishnakar, Srikanth, isar-users; +Cc: kas-devel
On 28.02.23 06:58, Krishnakar, Srikanth wrote:
> Hello,
>
> Can we build Isar-based projects using kas-container+podman but without
> any privilege escalations of any sorts on the host (container may do
> whatever it needs to as long as it is not running with --privileged) ?
>
Nope, already because of missing namespace support for binfmt_misc
(stalled once again after https://lkml.org/lkml/2021/12/16/407).
I'm no longer up-to-date regarding how sbuild / schroot improved the
picture of going unprivileged inside podman one day, but there might be
still other roadblocks left.
Jan
--
Siemens AG, Technology
Competence Center Embedded Linux
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2023-02-28 8:56 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-02-28 5:58 Isar-based projects using kas-container and podman-rootless Krishnakar, Srikanth
2023-02-28 6:15 ` Jan Kiszka
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox