Skip to content

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

running systemd inside containers #7649

Closed
marco-a-itl opened this issue Jan 30, 2025 · 1 comment
Closed

running systemd inside containers #7649

marco-a-itl opened this issue Jan 30, 2025 · 1 comment

Comments

@marco-a-itl
Copy link

Is your feature request related to a problem? Please describe.

There are some cases of multi-service containers, derived from applications extracted from VMs, where it would be useful to allow running systemd inside the container, without requiring the privileged flag for security reasons.

Support for systemd inside containers has been extremely tricky and fragile for years. It is also dependent on OS features, like the presence of cgroup v2, and on the underlying container engine. Only podman declares official support, and regarding kubernetes distributions the situation is still fragmented and unclear.
Latest workarounds (like this one related to openshift) seem to be based on the recent introduction of user-namespaces, in addition to the presence of cgroup v2.

Describe the solution you'd like

This is more of a question: is there some kind of support for pods that run systemd as PID 1, without requiring full privileges ?
Has anyone successfully run such kind of pods in rke2 ?

@dereknola
Copy link
Member

@rancher rancher locked and limited conversation to collaborators Jan 30, 2025
@dereknola dereknola converted this issue into discussion #7651 Jan 30, 2025

This issue was moved to a discussion.

You can continue the conversation there. Go to discussion →

Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants