You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker中subuid的工作原理及UID映射异常问题咨询

Understanding Docker's subuid Mechanism and Your UID Mapping Anomaly

How subuid Works in Docker

  • The /etc/subuid file assigns non-overlapping UID ranges to regular users, letting them run containers with isolated user namespaces without needing full root privileges on the host.
  • Each entry follows the format username:start_uid:range_size — in your case, incgnito:100000:65536 means user incgnito has access to 65536 UIDs starting from 100000 (covering 100000 to 165535 inclusive).
  • This range is used to map container-internal UIDs to host UIDs, preventing container users from accidentally accessing or modifying host resources owned by other system users.

Why Your Container's UID 0 Maps to Host UID 1000

Your uid_map output lays out exactly what's happening:

0 1000 1
1 100000 65536

Let's break down each line:

  • 0 1000 1: Maps container UID 0 (root) directly to host UID 1000 (your incgnito user) for 1 UID.
  • 1 100000 65536: Maps container UIDs 1 through 65536 to host UIDs 100000 through 165535.

This is Docker's default user namespace mapping behavior when running containers as a regular user:

  • It prioritizes mapping the container's root user to the host user that launched the container (your UID 1000). This ensures the container's root only has the same level of access to host resources as your regular user, not full host root privileges — a critical security safeguard.
  • The remaining container UIDs are mapped to the range defined in /etc/subuid for your user.

How to Map Container UID 0 to Host UID 100000 (If Needed)

If you want container root to map to the start of your subuid range instead, you can override the default mapping in two ways:

  1. Per-container override: Use the --uidmap flag when starting the container:
    docker run --uidmap 0:100000:1 --uidmap 1:100001:65535 -it <your-image>
    
    This explicitly maps container UID 0 to host UID 100000, and the rest of the container UIDs to the remainder of your subuid range.
  2. Global daemon configuration: Set up a consistent mapping for all containers by editing /etc/docker/daemon.json:
    {
      "userns-remap": "incgnito"
    }
    
    After saving the file, restart the Docker daemon with sudo systemctl restart docker. This will configure Docker to map container UID 0 to the first UID in your subuid range (100000) by default.

Verifying the Mapping

To confirm the mapping is working as expected:

  • Inside the container, run id to check your container UID.
  • On the host, find the container's main process ID with docker inspect -f '{{.State.Pid}}' <container-name>, then run cat /proc/<pid>/uid_map to see the exact mapping, or ps aux | grep <pid> to view the host UID associated with the container process.

内容的提问来源于stack exchange,提问作者rohit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 22:33:15