`distrobox create name example nvidia
distrobox create --name example-nvidia-toolkit --additional-flags "--runtime=nvidia -e NVIDIA_VISIBLE_DEVICES=all -e NVIDIA_DRIVER_CAPABILITIES=all" --image nvidia/cudadistrobox create --name example-nvidia-toolkit --additional-flags "--runtime=nvidia -e NVIDIA_VISIBLE_DEVICES=all -e NVIDIA_DRIVER_CAPABILITIES=all" --image nvidia/cuda--user root:root--userns keep-id and --user root:root which means your user maps to itself and root maps to rootdistrobox with --root/etc/nvidia-container-runtime/config.toml to remove no-cgroups = true ?
:NOPASSWD on sudo anywaysudo will just not ask anyway

podman create
--hostname "ubuntu-latest.toronto.hq.akdev.xyz"
--name "ubuntu-latest"
--privileged
--security-opt label=disable
--user root:root
--ipc host
--network host
--pid host
--label "manager=distrobox"
--env "SHELL=/usr/bin/zsh"
--env "HOME=/var/home/akdev"
--volume /:/run/host:rslave
--volume /dev:/dev:rslave
--volume /sys:/sys:rslave
--volume /tmp:/tmp:rslave
--volume "/usr/bin/distrobox-init":/usr/bin/entrypoint:ro
--volume "/usr/bin/distrobox-export":/usr/bin/distrobox-export:ro
--volume "/usr/bin/distrobox-host-exec":/usr/bin/distrobox-host-exec:ro
--volume "/var/home/akdev":"/var/home/akdev":rslave
--volume /sys/fs/selinux
--volume /var/log/journal
--volume /run/user/1000:/run/user/1000:rslave
--volume /etc/hosts:/etc/hosts:ro
--volume /etc/resolv.conf:/etc/resolv.conf:ro
--ulimit host
--annotation run.oci.keep_original_groups=1
--mount type=devpts,destination=/dev/pts
--userns keep-id --device=nvidia.com/gpu=all
--entrypoint /usr/bin/entrypoint
ubuntu:latest
--verbose
--name "akdev"
--user 1000
--group 1000
--home "/var/home/akdev"
--init "0"
--nvidia "0"
--pre-init-hooks ""
--additional-packages ""
-- ''Error: OCI runtime error: unable to start container "097cd5ee14db0b0a102b7f9cd6b9e1eba6d9d409a46466ee48ce7f3910059dd4": crun: error executing hook `/usr/bin/nvidia-container-runtime-hook` (exit code: 1)--user root:root--user root:root--userns keep-iddistrobox--root/etc/nvidia-container-runtime/config.tomlno-cgroups = true:NOPASSWDsudo