[–] [S] 1 point 2 days ago* (last edited 2 days ago) (6 children)

OK now this would make some sense but would definitely be a bit of a show stopper for me. I'll give it a try though.

Edit: Unfortunately this didn't solve the issue. I thought it did for a minute, but it was the browser cache I think auto-filling the correct result.

  • source
  • parent
  • context
  • [–] [S] 1 point 2 days ago (1 child)

    I think I have uids set up, but I'm not positive they're set up correctly.

    Here's an example of /etc/subuid for example, with it a bit anonymised for my specific user setup:

    core:524288:65536
    syncthing:589824:65536
    userA:655360:65536
    userB:720896:65536
    userC:786432:65536
    

    Syncthing in this case isn't running any podman containers, all sharing is done bare-metal. userA is working, but userB and userC do look like they're configured "correctly" at first glance. podman system info seems to be outputting the results above

      idMappings:
        gidmap:
        - container_id: 0
          host_id: 1101
          size: 1
        - container_id: 1
          host_id: 786432
          size: 65536
        uidmap:
        - container_id: 0
          host_id: 1101
          size: 1
        - container_id: 1
          host_id: 786432
          size: 65536
    

    Note: The user in question here is uid 1101, another new user I created for testing purposes.

  • source
  • parent
  • context
  • [–] [S] 3 points 2 days ago

    I mean, I might be wrong, but this only changes the mapping right? In the case that user broke containment, I would assume that they would have the user id of the user that's running the process?

    Granted this is all in theory so I'm not sure exactly -- that might be a perfectly reasonable way to do it.

  • source
  • parent
  • context
  • [–] [S] 1 point 2 days ago (1 child)

    As far as I understand, it should as it's embedded inside the actual image file and not mounted.

    I'm having other strange behaviour on non-1000 uid accounts. For example, running docker.io/library/httpd using the podman examples page on an account that isn't userid 1000 will create an issue where it complains that libgcc_0 isn't installed. This works flawlessly on the uid 1000 user.

    It does make me think that something needs to be configured for non-uid 1000 users on podman. This is not replicable on arch linux on my raspberry pi, fwiw.

  • source
  • parent
  • context
  •  

    Self cross-posting from: https://lemmy.zip/post/70909658

    Intention to have slightly better visibility from the self-hosted crowd and I'm interested in more general feedback on this too.

    Hey everyone! I'm trying to find a solution to a really confusing problem...

    I have the following simple nginx docker compose configuration on my Fedora home server that I can run without issue on my uid 1000 user, lets call this user "userA".

    services:
      nginx:
        container_name: nginx-alt
        image: docker.io/library/nginx
        restart: unless-stopped
        ports:
          - 8181:80
    

    This exposes internal port 80 as 8181 and can be accessed in a lan in the expected matter.

    However, for security reasons, I want to actually host this service eventually on a completely different user with less permissions. Let's call this user "userB" who has a very limited scope of the file system. This is to prevent potential escaping of the rootless container causing major file system havoc (i.e. reduce the scope of the user to a very limited network of containers.)

    The problem is really simple: For some reason, when userB runs this service (uid 1001), the nginx service suddenly complains about privileges. As a result, I get a "Forbidden 403" error when hosting. Turning off selinux has no affect (so setenforce 0 does nothing, meaning I can rule out secure linux interruption.)

    The errors look like the following:

    nginx-alt  | 2026/09/04 20:03:34 [error] 25#25: *1 "/usr/share/nginx/html/index.html" is forbidden (13: Permission denied), client: xx.xx.x.x, server: localhost, request: "GET / HTTP/1.1", host: "xxx.xxx.xxx.xxx:8181"
    nginx-alt  | 10.89.0.2 - - [04/Sep/2026:20:03:34 +0000] "GET / HTTP/1.1" 403 153 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:155.0) Gecko/20100101 Firefox/155.0" "-"
    

    For what it's worth, both users should be relatively vanilla and all ports are appropriately exported. There shouldn't be anything, for example, that is making userA run as "privileged" over the other users and podman should be running rootless in both containers.

    I did see a note on the nginx image about running in rootless that I might try, but it doesn't solve my bigger issue here which is the lack of consistency between the two users. Additionally, userns_mode: keep-ids only caused the container to fail to boot for other reason entirely.

    There must be something fundamentally wrong with my configuration of my system. Has anyone had any experience running two podman containers on two different users simultaneously that can provide feedback?

    Obviously, I'm not trying to run just an nginx server, but I found this to be the easiest configuration to reproduce.

     

    Hey everyone! I'm trying to find a solution to a really confusing problem...

    I have the following simple nginx docker compose configuration on my Fedora home server that I can run without issue on my uid 1000 user, lets call this user "userA".

    services:
      nginx:
        container_name: nginx-alt
        image: docker.io/library/nginx
        restart: unless-stopped
        ports:
          - 8181:80
    

    This exposes internal port 80 as 8181 and can be accessed in a lan in the expected matter.

    However, for security reasons, I want to actually host this service eventually on a completely different user with less permissions. Let's call this user "userB" who has a very limited scope of the file system. This is to prevent potential escaping of the rootless container causing major file system havoc (i.e. reduce the scope of the user to a very limited network of containers.)

    The problem is really simple: For some reason, when userB runs this service (uid 1001), the nginx service suddenly complains about privileges. As a result, I get a "Forbidden 403" error when hosting. Turning off selinux has no affect (so setenforce 0 does nothing, meaning I can rule out secure linux interruption.)

    The errors look like the following:

    nginx-alt  | 2026/09/04 20:03:34 [error] 25#25: *1 "/usr/share/nginx/html/index.html" is forbidden (13: Permission denied), client: xx.xx.x.x, server: localhost, request: "GET / HTTP/1.1", host: "xxx.xxx.xxx.xxx:8181"
    nginx-alt  | 10.89.0.2 - - [04/Sep/2026:20:03:34 +0000] "GET / HTTP/1.1" 403 153 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:155.0) Gecko/20100101 Firefox/155.0" "-"
    

    For what it's worth, both users should be relatively vanilla and all ports are appropriately exported. There shouldn't be anything, for example, that is making userA run as "privileged" over the other users and podman should be running rootless in both containers.

    I did see a note on the nginx image about running in rootless that I might try, but it doesn't solve my bigger issue here which is the lack of consistency between the two users. Additionally, userns_mode: keep-ids only caused the container to fail to boot for other reason entirely.

    There must be something fundamentally wrong with my configuration of my system. Has anyone had any experience running two podman containers on two different users simultaneously that can provide feedback?

    Obviously, I'm not trying to run just an nginx server, but I found this to be the easiest configuration to reproduce.

     

    Hey everyone,

    Coming this November it will have been 2 years since I started this community. I started it as a trial run for lemmy having migrated from kbin way back when (fpgagaming specifically) and I'm glad to say that so far things have gone smoothly and the lemmy interface has been nice once I got used to it.

    I'd like to take some time to reflect on the community and how things have progressed. I know I'm a bit early but I expect to be very busy in November so I would prefer to do this now while it's fresh on my mind.

    But let me start by saying thank you to everyone who has subscribed, posted content or otherwise commented on articles here. It's been a smooth 2 years despite having no moderators beyond myself.

    Moderation Requests

    In note of that, however, I would like to recruit a few members to be moderators. Please let me know if you're interested. I haven't had to do any major interventions so far, but I do occasionally worry that things will crop up when I get busy with real life affairs. Power in numbers, I say, so I'd love to get more members to help out with moderation.

    Lemmy so far

    Lemmy has been great but there are still a few features I'd really love to have that a few other threadiverse servers have that I'd love to vocalize support for:

    • Events or Time Based Threads: There are times where events would be nice. For example, it would be really nice to highlight specific release dates for HD collections or hardware launches. More importantly, it would be wonderful to do retro game bookclub events or even community multiplayer events. Events would be wonderful for this as it would help organize the community.
    • Thread Tags: One reason I made Retro Gaming instead of FPGAGaming was to help populate the community with more threads. Since Lemmy is generally smaller, I think that broader communities generally make more sense. However, I think there's an argument to be made that tags would help members filter out articles of specific sub categories. I think this has been talked to death, but I'd like to vocalize support for this.
    • Migration: Lastly, I feel like we still lack tools for community migration. This is a known issue in the community and I know it's being worked on.

    Overall, there's not a lot else to say on this. Lemmy has overall served us well.

    Content

    Regarding the content of Retro Gaming, I'd love to hear some feedback on the content we have so far and what people would like to see more of. I'd love people to share, for example, retro game hauls or pictures of retro gaming setups. Let me know if there's any content you'd like to see more of or if there are any requests for community events.

    Lastly, I'm looking to update our community icon and background. That should happen sometime in the next two months.

    Hope you all had a good weekend!

    view more: next ›