Search
Setup for Free
UB
Universal Blue
•
2y ago
antheas
rootless?
rootless
?
Universal Blue
Join
Universal Blue is a manufacturing process that focuses on community-driven desktop and server operating systems.
26,747
Members
View on Discord
Similar Threads
Was this page helpful?
Yes
No
© 2026 Hedgehog Software, LLC
Twitter
GitHub
Discord
System
Light
Dark
More
Communities
Docs
About
Terms
Privacy
A
antheas
OP
•
6/29/24, 10:18 AM
never use the rootless ver
, its garbage
P
Pez
•
6/29/24, 10:22 AM
it
's not really a bug
A
antheas
OP
•
6/29/24, 10:24 AM
the fact that the rootless ver exists means that you always need to type sudo and remember which one is which
A
antheas
OP
•
6/29/24, 10:24 AM
whereas with docker its always sudo
P
Pez
•
6/29/24, 10:24 AM
undesired behavior yes
, but this is exactly what is meant to happen when podman
(or anything else
) interacts with another filesystem while not necessarily being enlightened about it
A
antheas
It's possible for everything to not work after undocking
M
Madao
•
6/29/24, 10:24 AM
dam
A
antheas
OP
•
6/29/24, 10:25 AM
doesnt have to do with the filesystem
A
antheas
OP
•
6/29/24, 10:25 AM
rootless messes with permissions
A
antheas
OP
•
6/29/24, 10:25 AM
encodes them differently
P
Pez
•
6/29/24, 10:26 AM
and those permissions have to do with the FS
, this applies beyond the scope of just podman
A
antheas
OP
•
6/29/24, 10:26 AM
i tried using rootless for the project im working on
P
Pez
•
6/29/24, 10:26 AM
rootless is not great
A
antheas
OP
•
6/29/24, 10:26 AM
i found 0 benefit and it only caused issues
A
antheas
OP
•
6/29/24, 10:26 AM
alias podman
=
'sudo podman
'
P
Pez
•
6/29/24, 10:26 AM
LOL
A
antheas
OP
•
6/29/24, 10:27 AM
its meant for obscure RHEL deployments that cant use sudo for one reason or other
A
antheas
OP
•
6/29/24, 10:27 AM
also podman launches a daemon which blocks you from unmounting devices
A
antheas
OP
•
6/29/24, 10:27 AM
but other than that its daemonless
A
antheas
OP
•
6/29/24, 10:27 AM
ok
A
antheas
its meant for obscure RHEL deployments that cant use sudo for one reason or othe...
P
Pez
•
6/29/24, 10:27 AM
i would have to agree with that assessment
A
antheas
OP
•
6/29/24, 10:28 AM
so i get 0 of the daemon benefits and all of the daemon disadvantages
A
antheas
OP
•
6/29/24, 10:28 AM
at least with docker i have a service i can turn off
P
Pez
•
6/29/24, 10:28 AM
i guess if you
're doing like
. edge deployments
. it
's kinda a non
-concern too
.
A
antheas
OP
•
6/29/24, 10:28 AM
like using podman instead of docker
? yes
P
Pez
•
6/29/24, 10:28 AM
idk i guess i
'd rather have the option to use rootless at all than no option
A
antheas
OP
•
6/29/24, 10:29 AM
no
, if you have root perms it should always be root
A
antheas
OP
•
6/29/24, 10:29 AM
it should priviledge escalate
A
antheas
OP
•
6/29/24, 10:29 AM
and hide rootless behind a feature flag
P
Pez
•
6/29/24, 10:29 AM
right so we both agree it should still be a thing
A
antheas
rootless?
D
DevilFish303
•
6/29/24, 10:29 AM
its not 100
% rootless
D
DevilFish303
•
6/29/24, 10:30 AM
running as root inside the container
A
antheas
OP
•
6/29/24, 10:30 AM
did you launch podman with root or not
?
P
Pez
•
6/29/24, 10:30 AM
i
'm not saying it
's a sane default or useful for this env at all but having rootless is probably good for certain engineers
D
DevilFish303
•
6/29/24, 10:30 AM
nop
, i launched with normal user
A
antheas
OP
•
6/29/24, 10:30 AM
thats the issue
P
Pez
•
6/29/24, 10:30 AM
:
(
D
DevilFish303
•
6/29/24, 10:30 AM
why does cp work then
?
D
DevilFish303
•
6/29/24, 10:30 AM
im not performing sudo cp
, the permissions are fine
V
Valerie
•
6/29/24, 10:30 AM
P
Pez
•
6/29/24, 10:30 AM
because your host isn
't going out of its way to prevent any of this
A
antheas
OP
•
6/29/24, 10:30 AM
you get permission funnies because the container cant access stuff you copy
D
DevilFish303
•
6/29/24, 10:31 AM
that
's not making any sense to me
, on the host im not doing anything with root
, not dolphin
, not the terminal
, yet it results in different permissions
A
antheas
OP
•
6/29/24, 10:31 AM
but you have access to the container storage because its running as your user
P
Pez
•
6/29/24, 10:32 AM
basically what
's happening is your host FS doesn
't have any clue about podman
's internal filesystem PIDs etc and vice versa
D
DevilFish303
•
6/29/24, 10:32 AM
ohhh
P
Pez
•
6/29/24, 10:32 AM
just because you can write to somewhere that isn
't mapped correctly doesn
't mean it
's correct behavior
A
antheas
OP
•
6/29/24, 10:32 AM
if you want your container to act as your user
A
antheas
OP
•
6/29/24, 10:32 AM
https://github.com/antheas/bazzite-upd/blob/master/builder/alias.sh
A
antheas
OP
•
6/29/24, 10:32 AM
https://github.com/antheas/bazzite-upd/blob/master/builder/Dockerfile
A
antheas
OP
•
6/29/24, 10:32 AM
i did it here
Next page