Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
DescriptionAlexey Tikhonov
2021-10-11 19:56:26 UTC
This bug was initially created as a copy of Bug #1859252
I am copying this bug because: to track backport to RHEL8
1. Proposed title of this feature request
Rootless Containers as Easy as Pie : just work out-of-the-box
3. What is the nature and description of the request?
The customer has meanwhile investigated the technology for his application and is now thinking
about the obstacles that still have to be overcome for productive use.
For enterprise environments it is typical to have a centralized user management and
podman requires to manage subuid/subgid on file level of the host where a container should run.
So since we are talking about a decentralized approach the customer has to take the effort and
taking care of a consistent user/group mapping all over his infrastructure.
In addition the customers environment delivers user home directories via NFS shares. This is quite
common in enterprise environments but not supported by podman atm.
4. Why does the customer need this? (List the business requirements here)
Customer wants to:
- minimize the management effort for subuid/subgid management
- simplify integration into the corporate environment
- have a more stable solution while using the podman as it comes out-of-the-box for business environments
5. How would the customer like to achieve this? (List the functional requirements here)
- A novel concept/implementation for subuid/subgid which works automatic
(that would allow a even a single user to run isolated workloads)
- A novel approach to container .vs fileystem-permissions, e.g. store subuid/subgid in ACLs
and work on all filesystems which support ACLs
- or encapsulate the filesystem in a filesystem-image in a single file (which is owned by the user)
- perhaps this functionality might be implemented directly into the kernel.
6. For each functional requirement listed, specify how Red Hat and the customer can test to confirm the requirement is successfully implemented.
- Since this is a suggestion for improvement, for which it is currently not foreseeable how it might be implemented, no information can be given yet.
7. Is there already an existing RFE upstream or in Red Hat Bugzilla?
- not known yet
8. Does the customer have any specific timeline dependencies and which release would they like to target (i.e. RHEL5, RHEL6)?
- no, asap
9. Is the sales team involved in this request and do they have any additional input?
- no
10. List any affected packages or components.
- podman
11. Would the customer be able to assist in testing this functionality if implemented?
- yes, customer is highly engaged and would support testing.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory (shadow-utils bug fix and enhancement update), and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHBA-2022:2021