devcontainers / devcontainers/cli

Podman: automatic `--userns=keep-id` breaks containers using host networking

Open
#1,301 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
3k
Forks
457
Avg merge
13h 17m
Merged PRs (30d)
6

Description

I'm facing an issue when using podman and `--network=host` combination:

## Environment

- `@devcontainers/cli`: 0.88.0
- Podman client/server: 5.7.1
- Host: WSL2
- Podman server: rootful

## Problem

For Podman on Linux and a non-root `remoteUser`, Dev Containers automatically adds:

```text
--security-opt label=disable --userns=keep-id
```

See https://github.com/devcontainers/cli/issues/1004 and https://github.com/microsoft/vscode-remote-release/issues/10399.

When the configuration also requires `--network=host`, the container fails to start.

## Minimal underlying reproducer

This fails:

```sh
podman run --rm \
--network=host \
--userns=keep-id \
docker.io/library/alpine:3.20 \
true
```

Error:

```text
crun: mount `sysfs` to `sys`: Operation not permitted: OCI permission denied
```

Without `--userns=keep-id`, it succeeds:

```sh
podman run --rm \
--network=host \
docker.io/library/alpine:3.20 \
true
```

The CLI-generated `podman run` command contains both:

```text
--userns=keep-id --network=host
```

The automatic argument is added in:

```text
src/spec-node/singleContainer.ts
getPodmanArgs()
```

## Expected behavior

Users must be able to prevent the CLI from adding `--userns=keep-id`.

## Possible fixes

No one is perfect I'm afraid.

1. Do not add `--userns=keep-id` when `--network=host` is present.
2. Add a setting or CLI option to disable automatic Podman arguments.
3. Respect an explicit `--userns=...` in `runArgs` and do not add `--userns=keep-id`.
4. Make automatic `--userns=keep-id` opt-in instead of unconditional for non-root users.

Big thanks.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.