If you application needs root to execute, with very few exceptions, it is already wrong.
If you application needs root to execute, with very few exceptions, it is already wrong.
edit: I joke, I love what containers accomplish, and working with Docker has been a joy (:
If you're in that boat, there isn't much you can do except work with it.
That's the case I had in mind when writing that quote.
That's not the case, either. And root inside the container != root outside the container. A completely new user:group namespace is created inside the container. This is, in very large part, what Linux namespaces are for.
Further, you can certainly have a root-owned file accessible to non-root users, via chmod bits.
There are only a handful of excuses, ever, to run a privileged container. If you're not 100% sure, then it is not one of those excuses.
No. root inside is root outside (if you can get outside). The behavior you describe only applies if you enable user namespace remapping, which docker doesn’t by default.