Note that the --userns=keep-id flag is used to ensure that the UID inside the container is not root but the user’s regular UID. Notice above that when I run the id command outside of the container, my groups include the eng group, but when the container is run, the eng group does not show up. From a security perspective, this is a good thing because if the container processes escaped, they would not have access to directories that I have group access to. If users want to grant access, they have a problem.
The issue is that it is difficult to grant access to the container to these directories. Creating an eng group inside of the container would not match the eng group on the host because the user namespace offsets the real group UID.
Luckily the OCI Runtime crun supports a special feature to leak these additional groups into the container.
If I set that annotation, my rootless Podman now has access to the volume, as seen below:
We use an annotation since the OCI Specification currently does not have a way to tell this to the OCI Runtime. We have suggested adding it to the specification. At this time, no other OCI Runtime other than crun can handle this, including runc. Perhaps in the future, this feature will get added to the OCI.
containers.conf
If the user wants to make all of their containers share the users groups, they could add this annotation to the containers.conf in their home directories.
Terminal window
$cat~/.config/containers/containers.conf
[containers]
annotations=["run.oci.keep_original_groups=1",]
Now even the default Podman can create content in the volume, and user processes outside of the container see the correct content.
Files created in your container will unfortunately be owned to your user and default group, to fix this set the group sticky bit on the parent directory so all created files will inherit the group.
sudo chmod g+s /mnt/data
Selinux issues
If you use selinux and map a data mount inside your container with :z you will most likely get errors like;
Error: lsetxattr(label=system_u:object_r:container_file_t:s0) /mnt/data: operation not permitted
I believe this is because you are not owner of the files, regardless of group mapping. You will need to pre-set the selinux context on these directories. See [[Podman and selinux]] for more.