Skip to content

Conversation

@dnlzro
Copy link
Contributor

@dnlzro dnlzro commented Sep 24, 2025

Description

Currently, the docs state that the --userns=keep-id option maps the rootless user's UID/GID to the same values inside the container, but they don’t make explicit that the container's init process itself runs as that mapped UID/GID.

This behaviour has caused some confusion (see #24934). In practice:

  • Without --userns=keep-id, rootless containers default to running as root inside the container (mapped to the host UID externally).
  • With --userns=keep-id, the init process runs as the host UID/GID inside the container, overriding the image’s USER instruction unless --user is explicitly set.

This PR updates the documentation to make that behaviour clear.

Does this PR introduce a user-facing change?

None

Fixes: containers#24934

Signed-off-by: Daniel Lazaro <git@dlazaro.ca>
@openshift-ci openshift-ci bot added the do-not-merge/release-note-label-needed Enforce release-note requirement, even if just None label Sep 24, 2025
Copy link
Member

@Honny1 Honny1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks, LGTM.

/LGTM

Please add to the PR description:

```release-note
None
```

@openshift-ci openshift-ci bot added release-note-none and removed do-not-merge/release-note-label-needed Enforce release-note requirement, even if just None labels Sep 25, 2025
@dnlzro
Copy link
Contributor Author

dnlzro commented Sep 25, 2025

/assign @giuseppe

Copy link
Member

@giuseppe giuseppe left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

@openshift-ci openshift-ci bot added the lgtm Indicates that a PR is ready to be merged. label Sep 25, 2025
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Sep 25, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: dnlzro, giuseppe, Honny1

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Sep 25, 2025
@openshift-merge-bot openshift-merge-bot bot merged commit af65d46 into containers:main Sep 25, 2025
40 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. lgtm Indicates that a PR is ready to be merged. release-note-none

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants