自建Podman GitLab Runner文件权限能力失效问题排查
问题:Podman-in-Podman GitLab Runner自行构建镜像后权限丢失
在隔离网络环境中搭建运行podman-in-podman的Podman GitLab Runner,用于构建内网所需的其他容器。已编写容器文件实现无根podman-in-podman,此前由管理员构建该镜像,现在希望通过GitLab流水线自行构建,避免每次安全团队更新UBI 8基础镜像时都需要求助管理员。
当前Podman Runner使用管理员构建的镜像可以正常构建其他镜像,但自行构建的podman-in-podman镜像无法正常运行:构建完成后检查/usr/bin/newuidmap的cap_setuid文件权限正常,但运行该镜像时权限丢失,执行podman命令时报错,提示该文件需具备setuid或文件权限能力。
简化后的流水线配置(复制自隔离网络,可能存在拼写错误)
podman:build image ${CI_REGISTRY_IMAGE}/podman:latest_built_by_IT_team script: - podman login -u ${CI_REGISTRY_USER} -p ${CI_REGISTRY_PASSWORD} ${CI_REGISTRY} - podman build . -f PodmanContainerFile -t ${CI_REGISTRY_IMAGE}/podman:test - podman push ${CI_REGISTRY)_IMAGE}/podman:test # 调试命令及输出 - podman run ${CI_REGISTRY_IMAGE}/podman:test getcap /usr/bin/newuidmap # 输出:/usr/bin/newuidmap cap_setuid=ep - podman run ${CI_REGISTRY_IMAGE}/podman:test getfattr -d -m '' -- /usr/bin/newuidmap # 输出: # # file: usr/bin/newuidmap # security.capability=0sAQAAAoAAAAAAAAAAAAAAAAAAAAA= # security.selinux="system_u:object_r:container_file_t:s0" # getfattr: Removing leading '/' from absolute path names podman:test image: ${CI_REGISTRY_IMAGE}/podman:test needs: - podman:build script: # 以下调试命令显示cap_setuid已丢失 - getcap /usr/bin/newuidmap # 无输出 - getfattr -d -m '' -- /usr/bind/newuidmap # 输出: # getfattr: Removing leading '/' from absolute path names # # file: usr/bin/newuidmap # security.selinux="system_u:object_r:container_file_t:s0:c6,c945 - podman login -u ${CI_REGISTRY_USER} -p ${CI_REGISTRY_PASSWORD} ${CI_REGISTRY} # 报错: # time="some time" level=error msg="running `/usr/bin/newuidmap 33 0 1000 1 1 10000 55536`: newuidmap: write to uid_map failed: Operation not permitted" # Error: cannot set up namespace using "/usr/bin/newuidmap": should have setuid or have filecaps setuid: exit status 1
PodmanContainerFile配置
FROM <安全团队提供的UBI 8镜像> USER 0 # 隔离网络环境下配置仓库、证书等操作... RUN yum -y update && yum install -y podman crun attr && yum reinstall -y shadow-utils RUN useradd podman && \ echo podman:10000:55536 > /etc/subuid && \ echo podman:10000:55536 > /etc/subgid COPY --chmod=0644 podman-containers.conf /home/podman/.config/containers/containers.conf COPY --chmod=0644 containers.conf /etc/containers/containers.conf RUN mkdir -p /home/podman/.local/share/containers && \ chown podman:podman -R /home/podman VOLUME /var/lib/containers VOLUME /home/podman/.local/share/containers RUN sed -i -e 's/driver = "overlay"/driver = "vfs"/g' \ -e 's|^#mount_program|mount_program|g' \ -e '/additionalimage.*/a "var/lib/shared",' \ -e 's|^mountopt[[:space:]]*=.*$|mountopt = "nodev,fsync=0"|g' \ /etc/containers/storage.conf RUN mkdir -p /var/lib/shared/overlay-images \ /var/lib/shared/overlay-layers \ /var/lib/shred/vfs-images \ /var/lib/shared/vfs-layers && \ touch /var/lib/shared/overlay-images/images.lock \ /var/lib/shared/overlay-layers/layers.lock \ /var/lib/shared/vfs-images/images.lock \ /var/lib/shared/vfs-layers/layers.lock && \ chmod 0755 /usr/bin/fusermount3 ENV _CONTAINERS_USERNS_CONFIGURED="" USER 1000 WORKDIR /home/podman
podman-containers.conf配置
[containers] volumes = [ "/proc:/proc", ]
containers.conf配置
[containers] netns="host" userns="host" ipcns="host" utsns="host" cgroupns="host" cgroups="diabled" log_driver="k8s-file" [engine] cgroup_manager="cgroupfs" events_logger="file" runtime="crun"
内容的提问来源于stack exchange,提问作者NateW
相关产品推荐
相关产品推荐

