I am wondering though? Is there something like systemd-nspawn that doesn't require root?
I am wondering though? Is there something like systemd-nspawn that doesn't require root?
But is there a way to also run OCI compatible directly on this as well?
I don't have root on that system and so I can't create a chroot , there is fakeroot but it doesn't work since it uses qemu on that locked system.
Are there any other alternatives
You actually don't as long as you have user namespaces.
One thing I am working on I use chroot (rather unshare --root=) to minimally sandbox a subprocess. At the beginning of the script I have this little snippet:
if [ "$(id --user)" -ne 0 ]; then
exec unshare --map-root-user --mount -- "$0" "$@"
fi
Though you can probably just do something roughtly as `unshare --map-root-user --root=<PATH>`.Until then, I'm not sure if there is anything lightweight. If you don't need lightweight, there is Podman.
I am on a completely rootless client at one of my servers.
docker and the rootless nonsense is just root daemons and suid.
...would never have believed marketing lies would reach linux tools if anyone told me this before 2018.
There is podman but it requires one time root.
There's also https://github.com/termux/proot-distro which may or may not count as containers depending on how you define the word but I think it does count
yeah you can do some smaller fakechroot and maybe some bind mounts... if you call that a "container" good for you.
Sure looks like it works?
$ unshare -i -n -p -u -T -r -f
# ls
# id
gid=0(root) groups=0(root),65534(nogroup)
# ip -br a
lo DOWN
> yeah you can do some smaller fakechroot and maybe some bind mounts... if you call that a "container" good for you.Why are you being condescending about what constitutes a container?