python / python/devguide

Feature: Document SELinux bind-mount note for local devcontainer usage

Open Beginner friendly
#1,879 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type-feature
Dominant language
Python
Stars
2.1k
Forks
1k
Avg merge
2d 12h
Merged PRs (30d)
12

Description

Describe the enhancement or feature you would like

When using the CPython devcontainer image on SELinux-enabled Linux hosts, a plain bind mount may fail with Permission denied inside the container.

Example:

docker run -it --rm \
  -v "$PWD:/workspace" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest

In that case, a SELinux-compatible bind mount works:

  docker run -it --rm \
  -v "$PWD:/workspace:Z" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest

Without relabeling, /workspace may not be readable from inside the container.

It may be helpful to add a short note to the local Docker/devcontainer documentation for SELinux-enabled hosts, preferably using the :Z bind-mount form.

Describe alternatives you have considered

As an alternative workaround, this also works:

docker run -it --rm \
  --security-opt label=disable \
  -v "$PWD:/workspace" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest
Additional context

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Search the local Docker/devcontainer documentation for the bind-mount usage shown in the issue. Add a short note for SELinux-enabled Linux hosts using the :Z bind-mount form, and mention the label-disable workaround if appropriate. Done means the documentation explains why the plain mount can fail and shows a working command.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.