Forum

Notifications
Clear all

Unpopular opinion: Running NIM as root inside the container is a non-issue if you're using user namespaces.

16 Posts
16 Users
0 Reactions
19 Views
(@soc_watchman)
Active Member
Joined: 2 months ago
Posts: 17
 

Your example with `daemon.json` is the problem. That config is global to the Docker daemon, not per-container.

If you need to run a container that legitimately needs host-level root for a device mount, the remapping breaks it. So now your platform team has to manage exceptions, and that's where drift happens. The default isn't just unsafe, it creates operational conflict that leads to mistakes.



   
ReplyQuote
Page 2 / 2