You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非root用户在Docker容器中访问YubiKey的问题求助

解决Docker中非root用户访问YubiKey的权限问题

问题背景

宿主机环境中YubiKey可正常使用,ykman info输出正常。但在Docker容器中,以root用户运行能识别YubiKey,切换到非root用户时提示Error: No YubiKey detected!,pcscd日志核心报错为LIBUSB_ERROR_ACCESS,说明非root用户缺少USB设备访问权限。

解决方案

1. 调整Dockerfile,将用户加入设备权限组

修改Dockerfile,把创建的非root用户添加到plugdev组(Linux系统默认授予外部设备访问权限的组):

FROM ubuntu

USER root

RUN apt update && apt install -y yubikey-manager && rm -rf /var/lib/apt/lists/*

# 创建用户并加入plugdev组
RUN groupadd -r -g 1000 yubikey \
    && useradd --system --create-home --no-log-init -u 1000 -g 1000 yubikey \
    && usermod -aG plugdev yubikey

RUN mkdir /var/run/pcscd && chown yubikey:yubikey /var/run/pcscd

COPY --chown=root:root --chmod=755 entrypoint.sh /usr/local/bin/entrypoint.sh

USER yubikey

ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
CMD ykman info

2. 运行容器时映射宿主机设备与权限组

首先在宿主机查询plugdev组的ID:

getent group plugdev | cut -d: -f3

假设输出为46,执行以下命令启动容器:

docker run -it --rm \
  --device /dev/bus/usb:/dev/bus/usb \
  --group-add 46 \
  yubikey

3. 优化entrypoint脚本(可选)

调整脚本确保pcscd稳定后台运行:

#!/bin/bash

set -e
set -o pipefail

echo "Starting pcscd in background"
# 后台启动pcscd
pcscd --foreground --debug --apdu &
# 等待服务初始化
sleep 1
pcscd --hotplug

exec "$@"

原理说明

  • plugdev组是Linux系统中用于授予普通用户访问外部设备的默认组,YubiKey设备默认归属于该组;
  • 通过--group-add映射宿主机的plugdev组ID,确保容器内非root用户拥有匹配的设备访问权限;
  • 正确初始化pcscd服务,保证YubiKey的CCID接口能被容器内的ykman正常识别。

内容的提问来源于stack exchange,提问作者taylorjonl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 07:47:27