devcontainers / devcontainers/cli
Podman: automatic `--userns=keep-id` breaks containers using host networking
- Dominant language
- TypeScript
- Stars
- 3k
- Forks
- 457
- Avg merge
- 13h 17m
- Merged PRs (30d)
- 6
Description
I'm facing an issue when using podman and `--network=host` combination:
## Environment
- `@devcontainers/cli`: 0.88.0
- Podman client/server: 5.7.1
- Host: WSL2
- Podman server: rootful
## Problem
For Podman on Linux and a non-root `remoteUser`, Dev Containers automatically adds:
```text
--security-opt label=disable --userns=keep-id
```
See https://github.com/devcontainers/cli/issues/1004 and https://github.com/microsoft/vscode-remote-release/issues/10399.
When the configuration also requires `--network=host`, the container fails to start.
## Minimal underlying reproducer
This fails:
```sh
podman run --rm \
--network=host \
--userns=keep-id \
docker.io/library/alpine:3.20 \
true
```
Error:
```text
crun: mount `sysfs` to `sys`: Operation not permitted: OCI permission denied
```
Without `--userns=keep-id`, it succeeds:
```sh
podman run --rm \
--network=host \
docker.io/library/alpine:3.20 \
true
```
The CLI-generated `podman run` command contains both:
```text
--userns=keep-id --network=host
```
The automatic argument is added in:
```text
src/spec-node/singleContainer.ts
getPodmanArgs()
```
## Expected behavior
Users must be able to prevent the CLI from adding `--userns=keep-id`.
## Possible fixes
No one is perfect I'm afraid.
1. Do not add `--userns=keep-id` when `--network=host` is present.
2. Add a setting or CLI option to disable automatic Podman arguments.
3. Respect an explicit `--userns=...` in `runArgs` and do not add `--userns=keep-id`.
4. Make automatic `--userns=keep-id` opt-in instead of unconditional for non-root users.
Big thanks.
Contributor guide
Assessment
This issue has not been assessed yet.