Comment on Podman: Issues with multiple users running containers simultaneously
glizzyguzzler@piefed.blahaj.zone 7 hours ago
The best way to run Podman is root with UserNS to dole out UID/GID protection. Running Podman as root allows you to share networks between containers while having the containers run under different users. If you go rootless, you’d need to run under one user to share the user’s network space with all the containers you want.
As for your issue, I can’t really divine what the problem is from the errors. I avoid nginx because it’s coded to not play well with user abstraction and changing the user with the files it wants to write to etc. Gotta write into a ton of random folders! So not sure exactly what is up. But with Podman root it is easy to run as root 0 internally and make nginx think it has all the control it could ever want.
Try this setup (it is in Podman Quadlet format, apologies I don’t know the compose versions). It runs the container as root 0 internally, externally it runs as some random UID/GID - secure! It uses Volume idmap to map the internal root 0 user to 1001 for write access to the Volume.
Note that in Debian 13 symlinks are broken and won’t work with idmap, just point to the original source. If you need symlinks, I have an alternate UserNS that maps internal user root 0 to external user 1001 directly. You’d drop the idmap in Volume then and use that. You lose some extra security - now the container is running as external user 1001 instead of some random UID/GID - but that’s a pretty minor hit as long as your external user doesn’t have access to tons of things.
# Volumes to mount -> the @ is essential for saying "1001 is absolute and external" basically. 0 is internal. size of 1. You can map 1001 to 0 and 1002 to 1 with @1001-0-2, etc., etc., etc.
Volume=/mnt/something:/etc/nginx/wants/to/write/here:rw,noexec,nosuid,nodev,Z,idmap=uids=@1001-0-1;gids=@1001-0-1
# Run as user running the container
UserNS=auto
# [use this if req symlink b/c idmap does NOT work with symlinks] -> I tested and it is fixed in at least Podman v5.8.3, so Debian 14 will work with idmap and symlinks directly ! drop the idmap if using !
# UserNS=auto:uidmapping=0:@1001:1,gidmapping=0:@1001:1
# Security time
NoNewPrivileges=true
# https://man7.org/linux/man-pages/man7/capabilities.7.html
DropCapability=all
ReadOnly=true
ReadOnlyTmpfs=True
# These capabilities are needed for linuxserver's s6 "launcher" thing
#AddCapability=CAP_CHOWN
#AddCapability=CAP_DAC_OVERRIDE
#AddCapability=CAP_FOWNER
#AddCapability=CAP_SETGID
#AddCapability=CAP_SETUID
# Needs this if the container tries to bind below port 1024. I'm not sure if it is needed if it only tries to bind internally.
#AddCapability=CAP_NET_BIND_SERVICE
Root Podman and UserNS=auto needs a containers user to pull uid/gid from.
# Root Podman needs a `containers` "user" (not really a user, just a reserved uid/gid space)
sudo echo "containers:2147483647:2147483648" >> /etc/subuid
sudo echo "containers:2147483647:2147483648" >> /etc/subgid
The documentation for Podman is critically lacking in the “hobbyist” space. Hope this helps.
Note that sudo echo does not work as non root because the shell redirection is attempted before the command runs. You want
echo foo | sudo tee -a /barinstead