Skip to content

Podman: automatic --userns=keep-id breaks containers using host networking #1301

Description

@jankap

I'm facing an issue when using podman and --network=host combination:

Environment

  • @devcontainers/cli: 0.88.0
  • Podman client/server: 5.7.1
  • Host: WSL2
  • Podman server: rootful

Problem

For Podman on Linux and a non-root remoteUser, Dev Containers automatically adds:

--security-opt label=disable --userns=keep-id

See #1004 and microsoft/vscode-remote-release#10399.

When the configuration also requires --network=host, the container fails to start.

Minimal underlying reproducer

This fails:

podman run --rm \
  --network=host \
  --userns=keep-id \
  docker.io/library/alpine:3.20 \
  true

Error:

crun: mount `sysfs` to `sys`: Operation not permitted: OCI permission denied

Without --userns=keep-id, it succeeds:

podman run --rm \
  --network=host \
  docker.io/library/alpine:3.20 \
  true

The CLI-generated podman run command contains both:

--userns=keep-id --network=host

The automatic argument is added in:

src/spec-node/singleContainer.ts
getPodmanArgs()

Expected behavior

Users must be able to prevent the CLI from adding --userns=keep-id.

Possible fixes

No one is perfect I'm afraid.

  1. Do not add --userns=keep-id when --network=host is present.
  2. Add a setting or CLI option to disable automatic Podman arguments.
  3. Respect an explicit --userns=... in runArgs and do not add --userns=keep-id.
  4. Make automatic --userns=keep-id opt-in instead of unconditional for non-root users.

Big thanks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions