upvote
It feels so bad to see the "You need go give Chrome SUID Root for the sandbox to work". Setting a Web Browser SUID Root was an old joke about clueless users. It was the worst security screwup someone could imagine.
reply
Don't build your ide on electron then.
reply
podman seems to handle rootless namespaces just fine, minor caveat for some perf overhead but it's not the end of the world.
reply
And volumes. Volumes are not fun with podman. Ironically my team tried GitHub Codespaces and never looked back. Super cheap and uses DevContainers.
reply
What's the difference between Podman and docker for volumes? Other than needing to add Z to get volumes to mount with SELinux
reply
If you're root on a system and use Docker volumes, you can always `sudo ls` and access those volumes outside of the container.

If you're just a user running containers under Podman, it's more tricky.

reply
Maybe permissions when going rootlesz?
reply