On my server, I’ve noticed that I can run docker commands like docker compose up -d or docker run hello-world without root (sudo, su, etc), as if I had done the rootless setup, but docker info reveals “context: default”. I am also not using userns-remap. Any theories for what’s going on here?

Edit: [Solved] @cosmicrose@lemmy.blahaj.zone pointed out that users in the docker group can run commands without sudo, after checking, my user is indeed in the group.

      • groet@feddit.org
        link
        fedilink
        arrow-up
        7
        ·
        1 day ago

        Just as a security note: being in the docker group allows root access. If your user is not already a sudoer anyway, they can get root through docker.

        So if you run malicious code (like running a bad install script from the wrong github repo or installing the wrong dependency) as that user the attacker can escalate to root without knowing the user password.

        (The trick is to create a container and mount /. Then you can edit whatever files you want inside of the container, like editing /etc/passwd and setting a known password for the root user)

  • SinTan1729@programming.dev
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    The question has been answered. But since you seem to be new to containers, I’ll just give you a recommendation. Just use podman. It can do pretty much everything that docker is used for, but it’s rootless by default.

    • IronKrill@lemmy.ca
      link
      fedilink
      arrow-up
      2
      ·
      8 hours ago

      Question since you seem to know more than the average, is Podman not harder to set up? It’s part of what has held me off from it, because I’ve heard it’s more difficult to achieve things with it than Docker. Is that wrong?

      • SinTan1729@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        7 hours ago

        For most “normal” setups, no. Networks, environment variables, volumes, permissions etc. map pretty much one-to-one.

        If you’re using compose, you can even keep your setup mostly unchanged and use podman compose. Although, I would recommend learning a bit about quadlets and using them instead. There’s a tool called podlet that can help you translate your docker commands to quadlets, although it’s not complete and does miss some features. The annoying thing can be some QoL tooling that exists for docker compose that doesn’t for quadlets e.g. automatic restart for changed quadlet files. I wrote some scripts for most of these situations. I will probably release them at some point after I make sure that they don’t rely on any specific properties of my setup. But you can easily write them for yourself if you know some shell scripting.

        For docker run commands, you can mostly get away with changing it to podman run.