Hacker News
new
past
comments
ask
show
jobs
points
by
codedokode
5 hours ago
|
comments
by
jandrese
4 hours ago
|
next
[-]
It feels so bad to see the "You need go give Chrome SUID Root for the sandbox to work". Setting a Web Browser SUID Root was an old joke about clueless users. It was the worst security screwup someone could imagine.
reply
by
NewJazz
3 hours ago
|
prev
|
next
[-]
Don't build your ide on electron then.
reply
by
duped
4 hours ago
|
prev
|
[-]
podman seems to handle rootless namespaces just fine, minor caveat for some perf overhead but it's not the end of the world.
reply
by
internet101010
4 hours ago
|
parent
|
[-]
And volumes. Volumes are not fun with podman. Ironically my team tried GitHub Codespaces and never looked back. Super cheap and uses DevContainers.
reply
by
unethical_ban
2 hours ago
|
parent
|
[-]
What's the difference between Podman and docker for volumes? Other than needing to add Z to get volumes to mount with SELinux
reply
by
miki123211
2 minutes ago
|
parent
|
next
[-]
If you're root on a system and use Docker volumes, you can always `sudo ls` and access those volumes outside of the container.
If you're just a user running containers under Podman, it's more tricky.
reply
by
NewJazz
27 minutes ago
|
parent
|
prev
|
[-]
Maybe permissions when going rootlesz?
reply