You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

自建Podman GitLab Runner文件权限能力失效问题排查

问题:Podman-in-Podman GitLab Runner自行构建镜像后权限丢失

在隔离网络环境中搭建运行podman-in-podman的Podman GitLab Runner,用于构建内网所需的其他容器。已编写容器文件实现无根podman-in-podman,此前由管理员构建该镜像,现在希望通过GitLab流水线自行构建,避免每次安全团队更新UBI 8基础镜像时都需要求助管理员。

当前Podman Runner使用管理员构建的镜像可以正常构建其他镜像,但自行构建的podman-in-podman镜像无法正常运行:构建完成后检查/usr/bin/newuidmap的cap_setuid文件权限正常,但运行该镜像时权限丢失,执行podman命令时报错,提示该文件需具备setuid或文件权限能力。


简化后的流水线配置(复制自隔离网络,可能存在拼写错误)

podman:build
  image ${CI_REGISTRY_IMAGE}/podman:latest_built_by_IT_team
  script:
    - podman login -u ${CI_REGISTRY_USER} -p ${CI_REGISTRY_PASSWORD} ${CI_REGISTRY}
    - podman build . -f PodmanContainerFile -t ${CI_REGISTRY_IMAGE}/podman:test
    - podman push ${CI_REGISTRY)_IMAGE}/podman:test
    # 调试命令及输出
    - podman run ${CI_REGISTRY_IMAGE}/podman:test getcap /usr/bin/newuidmap
    # 输出:/usr/bin/newuidmap cap_setuid=ep
    - podman run ${CI_REGISTRY_IMAGE}/podman:test getfattr -d -m '' -- /usr/bin/newuidmap
    # 输出:
    # # file: usr/bin/newuidmap
    # security.capability=0sAQAAAoAAAAAAAAAAAAAAAAAAAAA=
    # security.selinux="system_u:object_r:container_file_t:s0"
    # getfattr: Removing leading '/' from absolute path names
    
podman:test
  image: ${CI_REGISTRY_IMAGE}/podman:test
  needs:
    - podman:build
  script:
    # 以下调试命令显示cap_setuid已丢失
    - getcap /usr/bin/newuidmap
    # 无输出
    - getfattr -d -m '' -- /usr/bind/newuidmap
    # 输出:
    # getfattr: Removing leading '/' from absolute path names
    # # file: usr/bin/newuidmap
    # security.selinux="system_u:object_r:container_file_t:s0:c6,c945
    - podman login -u ${CI_REGISTRY_USER} -p ${CI_REGISTRY_PASSWORD} ${CI_REGISTRY}
    # 报错:
    # time="some time" level=error msg="running `/usr/bin/newuidmap 33 0 1000 1 1 10000 55536`: newuidmap: write to uid_map failed: Operation not permitted"
    # Error: cannot set up namespace using "/usr/bin/newuidmap": should have setuid or have filecaps setuid: exit status 1

PodmanContainerFile配置

FROM <安全团队提供的UBI 8镜像>

USER 0
# 隔离网络环境下配置仓库、证书等操作...

RUN yum -y update && yum install -y podman crun attr && yum reinstall -y shadow-utils

RUN useradd podman && \
    echo podman:10000:55536 > /etc/subuid && \
    echo podman:10000:55536 > /etc/subgid
    
COPY --chmod=0644 podman-containers.conf /home/podman/.config/containers/containers.conf
COPY --chmod=0644 containers.conf /etc/containers/containers.conf

RUN mkdir -p /home/podman/.local/share/containers && \
    chown podman:podman -R /home/podman

VOLUME /var/lib/containers
VOLUME /home/podman/.local/share/containers

RUN sed -i -e 's/driver = "overlay"/driver = "vfs"/g' \
           -e 's|^#mount_program|mount_program|g' \
           -e '/additionalimage.*/a "var/lib/shared",' \
           -e 's|^mountopt[[:space:]]*=.*$|mountopt = "nodev,fsync=0"|g' \
           /etc/containers/storage.conf

RUN mkdir -p /var/lib/shared/overlay-images \
             /var/lib/shared/overlay-layers \
             /var/lib/shred/vfs-images \
             /var/lib/shared/vfs-layers && \
    touch /var/lib/shared/overlay-images/images.lock \
          /var/lib/shared/overlay-layers/layers.lock \
          /var/lib/shared/vfs-images/images.lock \
          /var/lib/shared/vfs-layers/layers.lock && \
    chmod 0755 /usr/bin/fusermount3

ENV _CONTAINERS_USERNS_CONFIGURED=""

USER 1000

WORKDIR /home/podman

podman-containers.conf配置

[containers]
volumes = [
    "/proc:/proc",
]

containers.conf配置

[containers]
netns="host"
userns="host"
ipcns="host"
utsns="host"
cgroupns="host"
cgroups="diabled"
log_driver="k8s-file"
[engine]
cgroup_manager="cgroupfs"
events_logger="file"
runtime="crun"

内容的提问来源于stack exchange,提问作者NateW

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 20:45:54