permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
First time poster. Coming from Docker background, using Podman since May of this year. Help me make sense of this. I am testing applying certs to a container in our dev environment, before replicating it to our production container. It was running as expected, and now I'm having issues when running the same commands (I've deleted the old container 1st before starting the work again). If I run the following command: sudo podman run -d -name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus.3:30.0 [usera@hosta /]$ sudo podman run --name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0 mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied Warning: Cannot open log file: ../sonatype-work/nexus3/log/jvm.log Warning: Forcing option -XX:LogFile=/tmp/jvm.log OpenJDK 64-Bit Server VM warning: Cannot open file ../sonatype-work/nexus3/log/jvm.log due to Permission denied java.io.FileNotFoundException: ../sonatype-work/nexus3/tmp/i4j_ZTDnGON8hezynsMX2ZCYAVDtQog=.lock (Permission denied) at java.io.RandomAccessFile.open0(Native Method) at java.io.RandomAccessFile.open(RandomAccessFile.java:316) at java.io.RandomAccessFile.<init>(RandomAccessFile.java:243) at com.install4j.runtime.launcher.util.SingleInstance.check(SingleInstance.java:72) at com.install4j.runtime.launcher.util.SingleInstance.checkForCurrentLauncher(SingleInstance.java:31) at com.install4j.runtime.launcher.UnixLauncher.checkSingleInstance(UnixLauncher.java:88) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:67) java.io.FileNotFoundException: /nexus-data/karaf.pid (Permission denied) at java.io.FileOutputStream.open0(Native Method) at java.io.FileOutputStream.open(FileOutputStream.java:270) at java.io.FileOutputStream.<init>(FileOutputStream.java:213) at java.io.FileOutputStream.<init>(FileOutputStream.java:101) at org.apache.karaf.main.InstanceHelper.writePid(InstanceHelper.java:127) at org.apache.karaf.main.Main.launch(Main.java:243) at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113) at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69) java.lang.RuntimeException: /nexus-data/log/karaf.log (Permission denied) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:102) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlersInternal(BootstrapLogManager.java:137) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlers(BootstrapLogManager.java:70) at org.apache.karaf.main.util.BootstrapLogManager.configureLogger(BootstrapLogManager.java:75) at org.apache.karaf.main.Main.launch(Main.java:244) at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113) at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69) Caused by: java.io.FileNotFoundException: /nexus-data/log/karaf.log (Permission denied) at java.io.FileOutputStream.open0(Native Method) at java.io.FileOutputStream.open(FileOutputStream.java:270) at java.io.FileOutputStream.<init>(FileOutputStream.java:213) at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.open(BootstrapLogManager.java:193) at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.<init>(BootstrapLogManager.java:182) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:100) ... 12 more Error creating bundle cache. Unable to update instance pid: Unable to create directory /nexus-data/instances Exception in thread "Thread-2" java.lang.SecurityException: Could not lock User prefs. Lock file access denied. at java.util.prefs.FileSystemPreferences.checkLockFile0ErrorCode(FileSystemPreferences.java:949) at java.util.prefs.FileSystemPreferences.lockFile(FileSystemPreferences.java:937) at java.util.prefs.FileSystemPreferences.sync(FileSystemPreferences.java:741) at java.util.prefs.FileSystemPreferences.flush(FileSystemPreferences.java:836) at java.util.prefs.FileSystemPreferences.syncWorld(FileSystemPreferences.java:476) at java.util.prefs.FileSystemPreferences.access$1200(FileSystemPreferences.java:50) at java.util.prefs.FileSystemPreferences$4$1.run(FileSystemPreferences.java:454) The following directories already exist on the host: /opt/nexus and /data/storage and are owned by nexus:nexus and the file permissions are 755. BUT, if I run the following command (with user 0): sudo podman run -dit --name hosta-nexus -u 0 -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0 Why was the container running without the -u 0, and now I'm getting permission denied at rootless? Is there something, somewhere that is persisting that is causing the issue? Also to clear things up, I'm opening the following port on the Container to the Host: 8081:80 , but if I type in localhost:8081 or localhost:80, the UI won't come up. I have to inspect the running container, get the IP address, and then put in that ip address:8081 and then the web pages comes up. I'm not sure what I'm doing incorrectly here. Thanks Chris
Hey Chris, The :Z changes makes volumes private to the container, it could be Selinux or it could be UID:GID issue for the bind mounts After you exit the container does the UID change for the files on the host? I'm not completely sure about this part but it may help you troubleshoot it. For the network issue, you can simply use VM_IP:8081, I wasn't able to replicate the issue on my laptop. Regards, Leon On Mon, 4 Oct, 2021, 23:31 Christopher.Miller@gd-ms.com, < Christopher.Miller@gd-ms.com> wrote:
First time poster. Coming from Docker background, using Podman since May of this year.
Help me make sense of this.
I am testing applying certs to a container in our dev environment, before replicating it to our production container. It was running as expected, and now I’m having issues when running the same commands (I’ve deleted the old container 1st before starting the work again).
If I run the following command:
sudo podman run -d –name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus.3:30.0
[usera@hosta /]$ sudo podman run --name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0
mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied
mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied
Warning: Cannot open log file: ../sonatype-work/nexus3/log/jvm.log
Warning: Forcing option -XX:LogFile=/tmp/jvm.log
OpenJDK 64-Bit Server VM warning: Cannot open file ../sonatype-work/nexus3/log/jvm.log due to Permission denied
java.io.FileNotFoundException: ../sonatype-work/nexus3/tmp/i4j_ZTDnGON8hezynsMX2ZCYAVDtQog=.lock (Permission denied)
at java.io.RandomAccessFile.open0(Native Method)
at java.io.RandomAccessFile.open(RandomAccessFile.java:316)
at java.io.RandomAccessFile.<init>(RandomAccessFile.java:243)
at com.install4j.runtime.launcher.util.SingleInstance.check(SingleInstance.java:72)
at com.install4j.runtime.launcher.util.SingleInstance.checkForCurrentLauncher(SingleInstance.java:31)
at com.install4j.runtime.launcher.UnixLauncher.checkSingleInstance(UnixLauncher.java:88)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:67)
java.io.FileNotFoundException: /nexus-data/karaf.pid (Permission denied)
at java.io.FileOutputStream.open0(Native Method)
at java.io.FileOutputStream.open(FileOutputStream.java:270)
at java.io.FileOutputStream.<init>(FileOutputStream.java:213)
at java.io.FileOutputStream.<init>(FileOutputStream.java:101)
at org.apache.karaf.main.InstanceHelper.writePid(InstanceHelper.java:127)
at org.apache.karaf.main.Main.launch(Main.java:243)
at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113)
at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:498)
at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69)
java.lang.RuntimeException: /nexus-data/log/karaf.log (Permission denied)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:102)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlersInternal(BootstrapLogManager.java:137)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlers(BootstrapLogManager.java:70)
at org.apache.karaf.main.util.BootstrapLogManager.configureLogger(BootstrapLogManager.java:75)
at org.apache.karaf.main.Main.launch(Main.java:244)
at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113)
at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:498)
at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69)
Caused by: java.io.FileNotFoundException: /nexus-data/log/karaf.log (Permission denied)
at java.io.FileOutputStream.open0(Native Method)
at java.io.FileOutputStream.open(FileOutputStream.java:270)
at java.io.FileOutputStream.<init>(FileOutputStream.java:213)
at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.open(BootstrapLogManager.java:193)
at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.<init>(BootstrapLogManager.java:182)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:100)
... 12 more
Error creating bundle cache.
Unable to update instance pid: Unable to create directory /nexus-data/instances
Exception in thread "Thread-2" java.lang.SecurityException: Could not lock User prefs. Lock file access denied.
at java.util.prefs.FileSystemPreferences.checkLockFile0ErrorCode(FileSystemPreferences.java:949)
at java.util.prefs.FileSystemPreferences.lockFile(FileSystemPreferences.java:937)
at java.util.prefs.FileSystemPreferences.sync(FileSystemPreferences.java:741)
at java.util.prefs.FileSystemPreferences.flush(FileSystemPreferences.java:836)
at java.util.prefs.FileSystemPreferences.syncWorld(FileSystemPreferences.java:476)
at java.util.prefs.FileSystemPreferences.access$1200(FileSystemPreferences.java:50)
at java.util.prefs.FileSystemPreferences$4$1.run(FileSystemPreferences.java:454)
The following directories already exist on the host: /opt/nexus and /data/storage and are owned by nexus:nexus and the file permissions are 755.
BUT, if I run the following command (with user 0):
sudo podman run -dit --name hosta-nexus -u 0 -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0
Why was the container running without the -u 0, and now I'm getting permission denied at rootless? Is there something, somewhere that is persisting that is causing the issue?
Also to clear things up, I’m opening the following port on the Container to the Host: 8081:80 , but if I type in localhost:8081 or localhost:80, the UI won’t come up. I have to inspect the running container, get the IP address, and then put in that ip address:8081 and then the web pages comes up. I’m not sure what I’m doing incorrectly here.
Thanks
Chris
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Leon, thanks for the reply. This website below helped me explain this for the SELinux :Z option: https://www.tutorialworks.com/podman-rootless-volumes/ I stopped the container, deleted it and created a new container and didn't notice any changes at this time for the UID for the directories on the host? Should I delete these directories, before creating a new container that will have bind mounts to them or is there a best practice for this? For the networking, and to get the UI, still doing what I detailed before. Thanks Chris From: Leon N <leon9923@gmail.com> Sent: Monday, October 4, 2021 9:47 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> Cc: podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey Chris, The :Z changes makes volumes private to the container, it could be Selinux or it could be UID:GID issue for the bind mounts After you exit the container does the UID change for the files on the host? I'm not completely sure about this part but it may help you troubleshoot it. For the network issue, you can simply use VM_IP:8081, I wasn't able to replicate the issue on my laptop. Regards, Leon On Mon, 4 Oct, 2021, 23:31 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: First time poster. Coming from Docker background, using Podman since May of this year. Help me make sense of this. I am testing applying certs to a container in our dev environment, before replicating it to our production container. It was running as expected, and now I'm having issues when running the same commands (I've deleted the old container 1st before starting the work again). If I run the following command: sudo podman run -d -name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus.3:30.0<http://docker.io/sonatype/nexus.3:30.0> [usera@hosta /]$ sudo podman run --name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0<http://docker.io/sonatype/nexus3:3.30.0> mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied Warning: Cannot open log file: ../sonatype-work/nexus3/log/jvm.log Warning: Forcing option -XX:LogFile=/tmp/jvm.log OpenJDK 64-Bit Server VM warning: Cannot open file ../sonatype-work/nexus3/log/jvm.log due to Permission denied java.io.FileNotFoundException: ../sonatype-work/nexus3/tmp/i4j_ZTDnGON8hezynsMX2ZCYAVDtQog=.lock (Permission denied) at java.io.RandomAccessFile.open0(Native Method) at java.io.RandomAccessFile.open(RandomAccessFile.java:316) at java.io.RandomAccessFile.<init>(RandomAccessFile.java:243) at com.install4j.runtime.launcher.util.SingleInstance.check(SingleInstance.java:72) at com.install4j.runtime.launcher.util.SingleInstance.checkForCurrentLauncher(SingleInstance.java:31) at com.install4j.runtime.launcher.UnixLauncher.checkSingleInstance(UnixLauncher.java:88) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:67) java.io.FileNotFoundException: /nexus-data/karaf.pid (Permission denied) at java.io.FileOutputStream.open0(Native Method) at java.io.FileOutputStream.open(FileOutputStream.java:270) at java.io.FileOutputStream.<init>(FileOutputStream.java:213) at java.io.FileOutputStream.<init>(FileOutputStream.java:101) at org.apache.karaf.main.InstanceHelper.writePid(InstanceHelper.java:127) at org.apache.karaf.main.Main.launch(Main.java:243) at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113) at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69) java.lang.RuntimeException: /nexus-data/log/karaf.log (Permission denied) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:102) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlersInternal(BootstrapLogManager.java:137) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlers(BootstrapLogManager.java:70) at org.apache.karaf.main.util.BootstrapLogManager.configureLogger(BootstrapLogManager.java:75) at org.apache.karaf.main.Main.launch(Main.java:244) at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113) at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:498) at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85) at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69) Caused by: java.io.FileNotFoundException: /nexus-data/log/karaf.log (Permission denied) at java.io.FileOutputStream.open0(Native Method) at java.io.FileOutputStream.open(FileOutputStream.java:270) at java.io.FileOutputStream.<init>(FileOutputStream.java:213) at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.open(BootstrapLogManager.java:193) at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.<init>(BootstrapLogManager.java:182) at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:100) ... 12 more Error creating bundle cache. Unable to update instance pid: Unable to create directory /nexus-data/instances Exception in thread "Thread-2" java.lang.SecurityException: Could not lock User prefs. Lock file access denied. at java.util.prefs.FileSystemPreferences.checkLockFile0ErrorCode(FileSystemPreferences.java:949) at java.util.prefs.FileSystemPreferences.lockFile(FileSystemPreferences.java:937) at java.util.prefs.FileSystemPreferences.sync(FileSystemPreferences.java:741) at java.util.prefs.FileSystemPreferences.flush(FileSystemPreferences.java:836) at java.util.prefs.FileSystemPreferences.syncWorld(FileSystemPreferences.java:476) at java.util.prefs.FileSystemPreferences.access$1200(FileSystemPreferences.java:50) at java.util.prefs.FileSystemPreferences$4$1.run(FileSystemPreferences.java:454) The following directories already exist on the host: /opt/nexus and /data/storage and are owned by nexus:nexus and the file permissions are 755. BUT, if I run the following command (with user 0): sudo podman run -dit --name hosta-nexus -u 0 -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0<http://docker.io/sonatype/nexus3:3.30.0> Why was the container running without the -u 0, and now I'm getting permission denied at rootless? Is there something, somewhere that is persisting that is causing the issue? Also to clear things up, I'm opening the following port on the Container to the Host: 8081:80 , but if I type in localhost:8081 or localhost:80, the UI won't come up. I have to inspect the running container, get the IP address, and then put in that ip address:8081 and then the web pages comes up. I'm not sure what I'm doing incorrectly here. Thanks Chris _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
On 10/4/21 13:58, Christopher.Miller@gd-ms.com wrote:
First time poster. Coming from Docker background, using Podman since May of this year.
Help me make sense of this.
I am testing applying certs to a container in our dev environment, before replicating it to our production container. It was running as expected, and now I’m having issues when running the same commands (I’ve deleted the old container 1^st before starting the work again).
If I run the following command:
sudo podman run -d –name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus.3:30.0
[usera@hosta /]$ sudo podman run --name hosta-nexus -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0
mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied
mkdir: cannot create directory '../sonatype-work/nexus3': Permission denied
Warning: Cannot open log file: ../sonatype-work/nexus3/log/jvm.log
Warning: Forcing option -XX:LogFile=/tmp/jvm.log
OpenJDK 64-Bit Server VM warning: Cannot open file ../sonatype-work/nexus3/log/jvm.log due to Permission denied
java.io.FileNotFoundException: ../sonatype-work/nexus3/tmp/i4j_ZTDnGON8hezynsMX2ZCYAVDtQog=.lock (Permission denied)
at java.io.RandomAccessFile.open0(Native Method)
at java.io.RandomAccessFile.open(RandomAccessFile.java:316)
at java.io.RandomAccessFile.<init>(RandomAccessFile.java:243)
at com.install4j.runtime.launcher.util.SingleInstance.check(SingleInstance.java:72)
at com.install4j.runtime.launcher.util.SingleInstance.checkForCurrentLauncher(SingleInstance.java:31)
at com.install4j.runtime.launcher.UnixLauncher.checkSingleInstance(UnixLauncher.java:88)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:67)
java.io.FileNotFoundException: /nexus-data/karaf.pid (Permission denied)
at java.io.FileOutputStream.open0(Native Method)
at java.io.FileOutputStream.open(FileOutputStream.java:270)
at java.io.FileOutputStream.<init>(FileOutputStream.java:213)
at java.io.FileOutputStream.<init>(FileOutputStream.java:101)
at org.apache.karaf.main.InstanceHelper.writePid(InstanceHelper.java:127)
at org.apache.karaf.main.Main.launch(Main.java:243)
at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113)
at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:498)
at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69)
java.lang.RuntimeException: /nexus-data/log/karaf.log (Permission denied)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:102)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlersInternal(BootstrapLogManager.java:137)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlers(BootstrapLogManager.java:70)
at org.apache.karaf.main.util.BootstrapLogManager.configureLogger(BootstrapLogManager.java:75)
at org.apache.karaf.main.Main.launch(Main.java:244)
at org.sonatype.nexus.karaf.NexusMain.launch(NexusMain.java:113)
at org.sonatype.nexus.karaf.NexusMain.main(NexusMain.java:52)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:498)
at com.exe4j.runtime.LauncherEngine.launch(LauncherEngine.java:85)
at com.install4j.runtime.launcher.UnixLauncher.main(UnixLauncher.java:69)
Caused by: java.io.FileNotFoundException: /nexus-data/log/karaf.log (Permission denied)
at java.io.FileOutputStream.open0(Native Method)
at java.io.FileOutputStream.open(FileOutputStream.java:270)
at java.io.FileOutputStream.<init>(FileOutputStream.java:213)
at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.open(BootstrapLogManager.java:193)
at org.apache.karaf.main.util.BootstrapLogManager$SimpleFileHandler.<init>(BootstrapLogManager.java:182)
at org.apache.karaf.main.util.BootstrapLogManager.getDefaultHandlerInternal(BootstrapLogManager.java:100)
... 12 more
Error creating bundle cache.
Unable to update instance pid: Unable to create directory /nexus-data/instances
Exception in thread "Thread-2" java.lang.SecurityException: Could not lock User prefs. Lock file access denied.
at java.util.prefs.FileSystemPreferences.checkLockFile0ErrorCode(FileSystemPreferences.java:949)
at java.util.prefs.FileSystemPreferences.lockFile(FileSystemPreferences.java:937)
at java.util.prefs.FileSystemPreferences.sync(FileSystemPreferences.java:741)
at java.util.prefs.FileSystemPreferences.flush(FileSystemPreferences.java:836)
at java.util.prefs.FileSystemPreferences.syncWorld(FileSystemPreferences.java:476)
at java.util.prefs.FileSystemPreferences.access$1200(FileSystemPreferences.java:50)
at java.util.prefs.FileSystemPreferences$4$1.run(FileSystemPreferences.java:454)
The following directories already exist on the host: /opt/nexus and /data/storage and are owned by nexus:nexus and the file permissions are 755.
BUT, if I run the following command (with user 0):
sudo podman run -dit --name hosta-nexus -u 0 -p 8081:80 -v /opt/nexus:/nexus-data:Z -v /data/storage:/storage:Z docker.io/sonatype/nexus3:3.30.0
Why was the container running without the -u 0, and now I'm getting permission denied at rootless? Is there something, somewhere that is persisting that is causing the issue?
Also to clear things up, I’m opening the following port on the Container to the Host: 8081:80 , but if I type in localhost:8081 or localhost:80, the UI won’t come up. I have to inspect the running container, get the IP address, and then put in that ip address:8081 and then the web pages comes up. I’m not sure what I’m doing incorrectly here.
Thanks
Chris
_______________________________________________ Podman mailing list --podman@lists.podman.io To unsubscribe send an email topodman-leave@lists.podman.io
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved.
Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved.
Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, < Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Thanks for the info, will try and report back. This is going to be off topic, however have to ask as SELinux continues to be something that I still don't have a solid grasp on, other then basics. I've worked heavily with RHEL 5/6/7 and typically SELinux and 3rd party apps were the big stumbling blocks for me. Just wondering what others have done to get up to speed on SELinux, especially with containers, and especially Podman and userspaces. Thanks From: Leon N <leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
Hey, So I still struggle with it sort off, but I did a lot of reading to grasp the basics then forced myself to setup services etc I still feel like I don't know a lot of things, but its all trial and error for me. This may help https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/htm... https://docs.fedoraproject.org/en-US/quick-docs/getting-started-with-selinux... Regards, Leon On Wed, 6 Oct, 2021, 18:15 Christopher.Miller@gd-ms.com, < Christopher.Miller@gd-ms.com> wrote:
Thanks for the info, will try and report back.
This is going to be off topic, however have to ask as SELinux continues to be something that I still don’t have a solid grasp on, other then basics. I’ve worked heavily with RHEL 5/6/7 and typically SELinux and 3rd party apps were the big stumbling blocks for me.
Just wondering what others have done to get up to speed on SELinux, especially with containers, and especially Podman and userspaces.
Thanks
*From:* Leon N <leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, < Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, <Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
From the host, xfs file system for /opt/nexus and /data/storage From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I'm reading up on overlay now) usera@hosta /]$ cat /etc/redhat-release ; podman info Red Hat Enterprise Linux release 8.1 (Ootpa) host: BuildahVersion: 1.9.0 Conmon: package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64 path: /usr/libexec/podman/conmon version: 'conmon version 2.0.1-dev, commit: unknown' Distribution: distribution: '"rhel"' version: "8.1" MemFree: 260805922816 MemTotal: 270091517952 OCIRuntime: package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64 path: /usr/bin/runc version: 'runc version spec: 1.0.1-dev' SwapFree: 8589930496 SwapTotal: 8589930496 arch: amd64 cpus: 56 hostname: hosta kernel: 4.18.0-147.5.1.el8_1.x86_64 os: linux rootless: true uptime: 116h 31m 31.21s (Approximately 4.83 days) registries: blocked: null insecure: null search: - hosta.XXX.enclave:8090 - registry.redhat.io - registry.access.redhat.com - quay.io - docker.io store: ConfigFile: /home/usera/.config/containers/storage.conf ContainerStore: number: 0 GraphDriverName: overlay GraphOptions: - overlay.mount_program=/usr/bin/fuse-overlayfs GraphRoot: /home/usera/.local/share/containers/storage GraphStatus: Backing Filesystem: xfs Native Overlay Diff: "false" Supports d_type: "true" Using metacopy: "false" ImageStore: number: 7 RunRoot: /run/user/2229 VolumePath: /home/usera/.local/share/containers/storage/volumes From: Daniel Walsh <dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 11:05 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com<mailto:dwalsh@redhat.com>; podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
If you move the location of storage to a different directlry you need to set the SELinux labels. # semanage fcontext -a -e /var/lib/containers/storage /storage # restorecon -R -v /storage Probably should add something like this to the storage.conf and to the man page. On 10/6/21 11:28, Christopher.Miller@gd-ms.com wrote:
From the host, xfs file system for /opt/nexus and /data/storage
From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I’m reading up on overlay now)
usera@hosta /]$ cat /etc/redhat-release ; podman info
Red Hat Enterprise Linux release 8.1 (Ootpa)
host:
BuildahVersion: 1.9.0
Conmon:
package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64
path: /usr/libexec/podman/conmon
version: 'conmon version 2.0.1-dev, commit: unknown'
Distribution:
distribution: '"rhel"'
version: "8.1"
MemFree: 260805922816
MemTotal: 270091517952
OCIRuntime:
package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64
path: /usr/bin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 8589930496
SwapTotal: 8589930496
arch: amd64
cpus: 56
hostname: hosta
kernel: 4.18.0-147.5.1.el8_1.x86_64
os: linux
rootless: true
uptime: 116h 31m 31.21s (Approximately 4.83 days)
registries:
blocked: null
insecure: null
search:
- hosta.XXX.enclave:8090
- registry.redhat.io
- registry.access.redhat.com
- quay.io
- docker.io
store:
ConfigFile: /home/usera/.config/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions:
- overlay.mount_program=/usr/bin/fuse-overlayfs
GraphRoot: /home/usera/.local/share/containers/storage
GraphStatus:
Backing Filesystem: xfs
Native Overlay Diff: "false"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 7
RunRoot: /run/user/2229
VolumePath: /home/usera/.local/share/containers/storage/volumes
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 11:05 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
What Filesystem is stored on /opt an d/nexus-data
Did you install storage in a different path then /var/lib/containers/storage.
I guess attaching podman info output would help.
On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, <Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Just so I understand. I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here? Thanks From: Daniel Walsh <dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:07 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you move the location of storage to a different directlry you need to set the SELinux labels. # semanage fcontext -a -e /var/lib/containers/storage /storage # restorecon -R -v /storage Probably should add something like this to the storage.conf and to the man page. On 10/6/21 11:28, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: From the host, xfs file system for /opt/nexus and /data/storage From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I'm reading up on overlay now) usera@hosta /]$ cat /etc/redhat-release ; podman info Red Hat Enterprise Linux release 8.1 (Ootpa) host: BuildahVersion: 1.9.0 Conmon: package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64 path: /usr/libexec/podman/conmon version: 'conmon version 2.0.1-dev, commit: unknown' Distribution: distribution: '"rhel"' version: "8.1" MemFree: 260805922816 MemTotal: 270091517952 OCIRuntime: package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64 path: /usr/bin/runc version: 'runc version spec: 1.0.1-dev' SwapFree: 8589930496 SwapTotal: 8589930496 arch: amd64 cpus: 56 hostname: hosta kernel: 4.18.0-147.5.1.el8_1.x86_64 os: linux rootless: true uptime: 116h 31m 31.21s (Approximately 4.83 days) registries: blocked: null insecure: null search: - hosta.XXX.enclave:8090 - registry.redhat.io - registry.access.redhat.com - quay.io - docker.io store: ConfigFile: /home/usera/.config/containers/storage.conf ContainerStore: number: 0 GraphDriverName: overlay GraphOptions: - overlay.mount_program=/usr/bin/fuse-overlayfs GraphRoot: /home/usera/.local/share/containers/storage GraphStatus: Backing Filesystem: xfs Native Overlay Diff: "false" Supports d_type: "true" Using metacopy: "false" ImageStore: number: 7 RunRoot: /run/user/2229 VolumePath: /home/usera/.local/share/containers/storage/volumes From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 11:05 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com<mailto:dwalsh@redhat.com>; podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
On 10/6/21 12:23, Christopher.Miller@gd-ms.com wrote:
Just so I understand.
I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here?
Thanks
Correct. I believe the issue you are having is in the podman storage, not inside of the container.
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 12:07 PM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
If you move the location of storage to a different directlry you need to set the SELinux labels.
# semanage fcontext -a -e /var/lib/containers/storage /storage
# restorecon -R -v /storage
Probably should add something like this to the storage.conf and to the man page.
On 10/6/21 11:28, Christopher.Miller@gd-ms.com wrote:
From the host, xfs file system for /opt/nexus and /data/storage
From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I’m reading up on overlay now)
usera@hosta /]$ cat /etc/redhat-release ; podman info
Red Hat Enterprise Linux release 8.1 (Ootpa)
host:
BuildahVersion: 1.9.0
Conmon:
package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64
path: /usr/libexec/podman/conmon
version: 'conmon version 2.0.1-dev, commit: unknown'
Distribution:
distribution: '"rhel"'
version: "8.1"
MemFree: 260805922816
MemTotal: 270091517952
OCIRuntime:
package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64
path: /usr/bin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 8589930496
SwapTotal: 8589930496
arch: amd64
cpus: 56
hostname: hosta
kernel: 4.18.0-147.5.1.el8_1.x86_64
os: linux
rootless: true
uptime: 116h 31m 31.21s (Approximately 4.83 days)
registries:
blocked: null
insecure: null
search:
- hosta.XXX.enclave:8090
- registry.redhat.io
- registry.access.redhat.com
- quay.io
- docker.io
store:
ConfigFile: /home/usera/.config/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions:
- overlay.mount_program=/usr/bin/fuse-overlayfs
GraphRoot: /home/usera/.local/share/containers/storage
GraphStatus:
Backing Filesystem: xfs
Native Overlay Diff: "false"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 7
RunRoot: /run/user/2229
VolumePath: /home/usera/.local/share/containers/storage/volumes
*From:* Daniel Walsh <dwalsh@redhat.com> <mailto:dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 11:05 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
What Filesystem is stored on /opt an d/nexus-data
Did you install storage in a different path then /var/lib/containers/storage.
I guess attaching podman info output would help.
On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, <Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
Well...this is embarrassing and want to be honest. Checked the host and SELinux is disabled. # sudo semanage fcontext -a -e /var/lib/containners/storage /data/storage ValueError: Equivalence class for /data/storage already exists # sudo restorecon -R -v /data/storage Still not sure why see ? for the files/directories when using ls -alZ against them. From: Daniel Walsh <dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:46 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. On 10/6/21 12:23, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Just so I understand. I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here? Thanks Correct. I believe the issue you are having is in the podman storage, not inside of the container. From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:07 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you move the location of storage to a different directlry you need to set the SELinux labels. # semanage fcontext -a -e /var/lib/containers/storage /storage # restorecon -R -v /storage Probably should add something like this to the storage.conf and to the man page. On 10/6/21 11:28, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: From the host, xfs file system for /opt/nexus and /data/storage From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I'm reading up on overlay now) usera@hosta /]$ cat /etc/redhat-release ; podman info Red Hat Enterprise Linux release 8.1 (Ootpa) host: BuildahVersion: 1.9.0 Conmon: package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64 path: /usr/libexec/podman/conmon version: 'conmon version 2.0.1-dev, commit: unknown' Distribution: distribution: '"rhel"' version: "8.1" MemFree: 260805922816 MemTotal: 270091517952 OCIRuntime: package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64 path: /usr/bin/runc version: 'runc version spec: 1.0.1-dev' SwapFree: 8589930496 SwapTotal: 8589930496 arch: amd64 cpus: 56 hostname: hosta kernel: 4.18.0-147.5.1.el8_1.x86_64 os: linux rootless: true uptime: 116h 31m 31.21s (Approximately 4.83 days) registries: blocked: null insecure: null search: - hosta.XXX.enclave:8090 - registry.redhat.io - registry.access.redhat.com - quay.io - docker.io store: ConfigFile: /home/usera/.config/containers/storage.conf ContainerStore: number: 0 GraphDriverName: overlay GraphOptions: - overlay.mount_program=/usr/bin/fuse-overlayfs GraphRoot: /home/usera/.local/share/containers/storage GraphStatus: Backing Filesystem: xfs Native Overlay Diff: "false" Supports d_type: "true" Using metacopy: "false" ImageStore: number: 7 RunRoot: /run/user/2229 VolumePath: /home/usera/.local/share/containers/storage/volumes From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 11:05 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com<mailto:dwalsh@redhat.com>; podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
On 10/6/21 15:32, Christopher.Miller@gd-ms.com wrote:
Well…this is embarrassing and want to be honest. Checked the host and SELinux is disabled.
# sudo semanage fcontext -a -e /var/lib/containners/storage /data/storage
ValueError: Equivalence class for /data/storage already exists
# sudo restorecon -R -v /data/storage
Still not sure why see ? for the files/directories when using ls -alZ against them.
I guess that is what ls shows when SELinux is disabled. I never disable it... :^) So must be some other reason your containers are blowing up. Did you try running with --privileged? Do they work with Docker?
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 12:46 PM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
On 10/6/21 12:23, Christopher.Miller@gd-ms.com wrote:
Just so I understand.
I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here?
Thanks
Correct. I believe the issue you are having is in the podman storage, not inside of the container.
*From:* Daniel Walsh <dwalsh@redhat.com> <mailto:dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 12:07 PM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
If you move the location of storage to a different directlry you need to set the SELinux labels.
# semanage fcontext -a -e /var/lib/containers/storage /storage
# restorecon -R -v /storage
Probably should add something like this to the storage.conf and to the man page.
On 10/6/21 11:28, Christopher.Miller@gd-ms.com wrote:
From the host, xfs file system for /opt/nexus and /data/storage
From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I’m reading up on overlay now)
usera@hosta /]$ cat /etc/redhat-release ; podman info
Red Hat Enterprise Linux release 8.1 (Ootpa)
host:
BuildahVersion: 1.9.0
Conmon:
package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64
path: /usr/libexec/podman/conmon
version: 'conmon version 2.0.1-dev, commit: unknown'
Distribution:
distribution: '"rhel"'
version: "8.1"
MemFree: 260805922816
MemTotal: 270091517952
OCIRuntime:
package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64
path: /usr/bin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 8589930496
SwapTotal: 8589930496
arch: amd64
cpus: 56
hostname: hosta
kernel: 4.18.0-147.5.1.el8_1.x86_64
os: linux
rootless: true
uptime: 116h 31m 31.21s (Approximately 4.83 days)
registries:
blocked: null
insecure: null
search:
- hosta.XXX.enclave:8090
- registry.redhat.io
- registry.access.redhat.com
- quay.io
- docker.io
store:
ConfigFile: /home/usera/.config/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions:
- overlay.mount_program=/usr/bin/fuse-overlayfs
GraphRoot: /home/usera/.local/share/containers/storage
GraphStatus:
Backing Filesystem: xfs
Native Overlay Diff: "false"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 7
RunRoot: /run/user/2229
VolumePath: /home/usera/.local/share/containers/storage/volumes
*From:* Daniel Walsh <dwalsh@redhat.com> <mailto:dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 11:05 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
What Filesystem is stored on /opt an d/nexus-data
Did you install storage in a different path then /var/lib/containers/storage.
I guess attaching podman info output would help.
On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, <Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
I'm not sure why, but I feel like your container is using its own user, which is why when you gave --user 0 it worked, since I see those files are owned by root, any chance the user inside the container is nexus or is it still root? On Thu, 7 Oct, 2021, 01:36 Daniel Walsh, <dwalsh@redhat.com> wrote:
On 10/6/21 15:32, Christopher.Miller@gd-ms.com wrote:
Well…this is embarrassing and want to be honest. Checked the host and SELinux is disabled.
# sudo semanage fcontext -a -e /var/lib/containners/storage /data/storage
ValueError: Equivalence class for /data/storage already exists
# sudo restorecon -R -v /data/storage
Still not sure why see ? for the files/directories when using ls -alZ against them.
I guess that is what ls shows when SELinux is disabled. I never disable it... :^)
So must be some other reason your containers are blowing up. Did you try running with --privileged?
Do they work with Docker?
*From:* Daniel Walsh <dwalsh@redhat.com> <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 12:46 PM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
On 10/6/21 12:23, Christopher.Miller@gd-ms.com wrote:
Just so I understand.
I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here?
Thanks
Correct. I believe the issue you are having is in the podman storage, not inside of the container.
*From:* Daniel Walsh <dwalsh@redhat.com> <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 12:07 PM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
If you move the location of storage to a different directlry you need to set the SELinux labels.
# semanage fcontext -a -e /var/lib/containers/storage /storage
# restorecon -R -v /storage
Probably should add something like this to the storage.conf and to the man page.
On 10/6/21 11:28, Christopher.Miller@gd-ms.com wrote:
From the host, xfs file system for /opt/nexus and /data/storage
From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I’m reading up on overlay now)
usera@hosta /]$ cat /etc/redhat-release ; podman info
Red Hat Enterprise Linux release 8.1 (Ootpa)
host:
BuildahVersion: 1.9.0
Conmon:
package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64
path: /usr/libexec/podman/conmon
version: 'conmon version 2.0.1-dev, commit: unknown'
Distribution:
distribution: '"rhel"'
version: "8.1"
MemFree: 260805922816
MemTotal: 270091517952
OCIRuntime:
package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64
path: /usr/bin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 8589930496
SwapTotal: 8589930496
arch: amd64
cpus: 56
hostname: hosta
kernel: 4.18.0-147.5.1.el8_1.x86_64
os: linux
rootless: true
uptime: 116h 31m 31.21s (Approximately 4.83 days)
registries:
blocked: null
insecure: null
search:
- hosta.XXX.enclave:8090
- registry.redhat.io
- registry.access.redhat.com
- quay.io
- docker.io
store:
ConfigFile: /home/usera/.config/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions:
- overlay.mount_program=/usr/bin/fuse-overlayfs
GraphRoot: /home/usera/.local/share/containers/storage
GraphStatus:
Backing Filesystem: xfs
Native Overlay Diff: "false"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 7
RunRoot: /run/user/2229
VolumePath: /home/usera/.local/share/containers/storage/volumes
*From:* Daniel Walsh <dwalsh@redhat.com> <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 11:05 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
What Filesystem is stored on /opt an d/nexus-data
Did you install storage in a different path then /var/lib/containers/storage.
I guess attaching podman info output would help.
On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> <leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, < Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
To me, its still root in the container. There is a UID:GID tied to 1005, which I can't identity from the id command, nor has an entry under /etc/passwd or /etc/group. Nexus has 200 for UID and GID within the container. Thanks From: Leon N <leon9923@gmail.com> Sent: Wednesday, October 6, 2021 9:08 PM To: dwalsh@redhat.com Cc: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. I'm not sure why, but I feel like your container is using its own user, which is why when you gave --user 0 it worked, since I see those files are owned by root, any chance the user inside the container is nexus or is it still root? On Thu, 7 Oct, 2021, 01:36 Daniel Walsh, <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> wrote: On 10/6/21 15:32, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Well...this is embarrassing and want to be honest. Checked the host and SELinux is disabled. # sudo semanage fcontext -a -e /var/lib/containners/storage /data/storage ValueError: Equivalence class for /data/storage already exists # sudo restorecon -R -v /data/storage Still not sure why see ? for the files/directories when using ls -alZ against them. I guess that is what ls shows when SELinux is disabled. I never disable it... :^) So must be some other reason your containers are blowing up. Did you try running with --privileged? Do they work with Docker? From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:46 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. On 10/6/21 12:23, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Just so I understand. I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here? Thanks Correct. I believe the issue you are having is in the podman storage, not inside of the container. From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:07 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you move the location of storage to a different directlry you need to set the SELinux labels. # semanage fcontext -a -e /var/lib/containers/storage /storage # restorecon -R -v /storage Probably should add something like this to the storage.conf and to the man page. On 10/6/21 11:28, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: From the host, xfs file system for /opt/nexus and /data/storage From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I'm reading up on overlay now) usera@hosta /]$ cat /etc/redhat-release ; podman info Red Hat Enterprise Linux release 8.1 (Ootpa) host: BuildahVersion: 1.9.0 Conmon: package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64 path: /usr/libexec/podman/conmon version: 'conmon version 2.0.1-dev, commit: unknown' Distribution: distribution: '"rhel"' version: "8.1" MemFree: 260805922816 MemTotal: 270091517952 OCIRuntime: package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64 path: /usr/bin/runc version: 'runc version spec: 1.0.1-dev' SwapFree: 8589930496 SwapTotal: 8589930496 arch: amd64 cpus: 56 hostname: hosta kernel: 4.18.0-147.5.1.el8_1.x86_64 os: linux rootless: true uptime: 116h 31m 31.21s (Approximately 4.83 days) registries: blocked: null insecure: null search: - hosta.XXX.enclave:8090 - registry.redhat.io<http://registry.redhat.io> - registry.access.redhat.com<http://registry.access.redhat.com> - quay.io<http://quay.io> - docker.io<http://docker.io> store: ConfigFile: /home/usera/.config/containers/storage.conf ContainerStore: number: 0 GraphDriverName: overlay GraphOptions: - overlay.mount_program=/usr/bin/fuse-overlayfs GraphRoot: /home/usera/.local/share/containers/storage GraphStatus: Backing Filesystem: xfs Native Overlay Diff: "false" Supports d_type: "true" Using metacopy: "false" ImageStore: number: 7 RunRoot: /run/user/2229 VolumePath: /home/usera/.local/share/containers/storage/volumes From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 11:05 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com<mailto:dwalsh@redhat.com>; podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
True, we all know its not best practice to disable SELinux, however this is our dev environment, so things aren't as ridged. However I was originally trying to run the container with SUDO only (this is rootless as I understand it), and the only way to get around the Nexus permission issues that I was seeing was to in addition to using SUDO, also use -u 0. I tried looking online, I can't find anything that references the difference between using -u 0 and -privileged. Thanks From: Daniel Walsh <dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 4:05 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. I guess that is what ls shows when SELinux is disabled. I never disable it... :^) So must be some other reason your containers are blowing up. Did you try running with --privileged? Do they work with Docker? From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:46 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. On 10/6/21 12:23, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Just so I understand. I created a generic directory /data/storage for the Nexus container to write to. So it sounds like the default storage for containers is /var/lib/containers/storage? And should be placing container storage here? Thanks Correct. I believe the issue you are having is in the podman storage, not inside of the container. From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 12:07 PM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. If you move the location of storage to a different directlry you need to set the SELinux labels. # semanage fcontext -a -e /var/lib/containers/storage /storage # restorecon -R -v /storage Probably should add something like this to the storage.conf and to the man page. On 10/6/21 11:28, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: From the host, xfs file system for /opt/nexus and /data/storage From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I'm reading up on overlay now) usera@hosta /]$ cat /etc/redhat-release ; podman info Red Hat Enterprise Linux release 8.1 (Ootpa) host: BuildahVersion: 1.9.0 Conmon: package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64 path: /usr/libexec/podman/conmon version: 'conmon version 2.0.1-dev, commit: unknown' Distribution: distribution: '"rhel"' version: "8.1" MemFree: 260805922816 MemTotal: 270091517952 OCIRuntime: package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64 path: /usr/bin/runc version: 'runc version spec: 1.0.1-dev' SwapFree: 8589930496 SwapTotal: 8589930496 arch: amd64 cpus: 56 hostname: hosta kernel: 4.18.0-147.5.1.el8_1.x86_64 os: linux rootless: true uptime: 116h 31m 31.21s (Approximately 4.83 days) registries: blocked: null insecure: null search: - hosta.XXX.enclave:8090 - registry.redhat.io - registry.access.redhat.com - quay.io - docker.io store: ConfigFile: /home/usera/.config/containers/storage.conf ContainerStore: number: 0 GraphDriverName: overlay GraphOptions: - overlay.mount_program=/usr/bin/fuse-overlayfs GraphRoot: /home/usera/.local/share/containers/storage GraphStatus: Backing Filesystem: xfs Native Overlay Diff: "false" Supports d_type: "true" Using metacopy: "false" ImageStore: number: 7 RunRoot: /run/user/2229 VolumePath: /home/usera/.local/share/containers/storage/volumes From: Daniel Walsh <dwalsh@redhat.com><mailto:dwalsh@redhat.com> Sent: Wednesday, October 6, 2021 11:05 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Cc: podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. What Filesystem is stored on /opt an d/nexus-data Did you install storage in a different path then /var/lib/containers/storage. I guess attaching podman info output would help. On 10/6/21 10:50, Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com> wrote: Here is my SELinux output both from the host and container. I'm getting a lot "?" characters on the host, when I think I should be seeing the user, role and type label defined. I've googled around based on those results and not finding anything. I've tried to restorecon -R -v on those volumes and nothing changed. Volume Mounts host: /opt/nexus container: /nexus-data host: /data/storage container: /storage From the host [usera@hosta /]$ sudo ls -alZ /opt/nexus [sudo] password for usera: total 24 drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 . drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 .. drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 14:48 port drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp [usera@hosta /]$ sudo ls -alZ /data/storage total 24 drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 . drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 .. -rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer -rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer From the container [root@6ca25b429eb1 /]# sestatus bash: sestatus: command not found [root@6ca25b429eb1 /]# whereis selinux selinux: /etc/selinux /usr/libexec/selinux [root@6ca25b429eb1 /]# ls -al /etc/selinux total 4 drwxr-xr-x 1 root root 6 Oct 6 13:49 . drwxr-xr-x 1 root root 21 Mar 4 2021 .. -rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf [root@6ca25b429eb1 /]# ls -alZ /nexus-data total 24 drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs -rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores -rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient -rw-r--r-- 1 root root ? 5 Oct 5 18:48 port drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp [root@6ca25b429eb1 /]# ls -laZ /storage total 24 drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 . drwxr-xr-x 1 root root ? 77 Oct 5 14:12 .. -rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer -rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer -rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks -rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem -rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer Thanks again From: Leon N <leon9923@gmail.com><mailto:leon9923@gmail.com> Sent: Wednesday, October 6, 2021 8:29 AM To: Miller, Christopher (NE) <Christopher.Miller@gd-ms.com><mailto:Christopher.Miller@gd-ms.com> Cc: dwalsh@redhat.com<mailto:dwalsh@redhat.com>; podman mailing list <podman@lists.podman.io><mailto:podman@lists.podman.io> Subject: Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host External E-mail --- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe. Hey, These would be run on the host You can also change the restorecon parameters to restore the contexts for the storage you mounted sudo restorecon -R -v <path to storage> Doing ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts Regards, Leon On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>, <Christopher.Miller@gd-ms.com<mailto:Christopher.Miller@gd-ms.com>> wrote: Sorry I'm not clear where I want to run these commands, on the host or the container? thanks From: Daniel Walsh <dwalsh@redhat.com<mailto:dwalsh@redhat.com>> Sent: Tuesday, October 5, 2021 7:10 PM To: podman@lists.podman.io<mailto:podman@lists.podman.io> Subject: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers Might fix it. You can run `sudo ausearch -m avc -ts recent` After it fails to see if SELinux is involved. _______________________________________________ Podman mailing list -- podman@lists.podman.io<mailto:podman@lists.podman.io> To unsubscribe send an email to podman-leave@lists.podman.io<mailto:podman-leave@lists.podman.io>
https://github.com/containers/storage/pull/1038 On 10/6/21 11:28, Christopher.Miller@gd-ms.com wrote:
From the host, xfs file system for /opt/nexus and /data/storage
From the container, noticed that /storage is xfs but /opt/sonatype shows overlay (I’m reading up on overlay now)
usera@hosta /]$ cat /etc/redhat-release ; podman info
Red Hat Enterprise Linux release 8.1 (Ootpa)
host:
BuildahVersion: 1.9.0
Conmon:
package: podman-1.4.2-5.module+el8.1.0+4240+893c1ab8.x86_64
path: /usr/libexec/podman/conmon
version: 'conmon version 2.0.1-dev, commit: unknown'
Distribution:
distribution: '"rhel"'
version: "8.1"
MemFree: 260805922816
MemTotal: 270091517952
OCIRuntime:
package: runc-1.0.0-60.rc8.module+el8.1.0+4081+b29780af.x86_64
path: /usr/bin/runc
version: 'runc version spec: 1.0.1-dev'
SwapFree: 8589930496
SwapTotal: 8589930496
arch: amd64
cpus: 56
hostname: hosta
kernel: 4.18.0-147.5.1.el8_1.x86_64
os: linux
rootless: true
uptime: 116h 31m 31.21s (Approximately 4.83 days)
registries:
blocked: null
insecure: null
search:
- hosta.XXX.enclave:8090
- registry.redhat.io
- registry.access.redhat.com
- quay.io
- docker.io
store:
ConfigFile: /home/usera/.config/containers/storage.conf
ContainerStore:
number: 0
GraphDriverName: overlay
GraphOptions:
- overlay.mount_program=/usr/bin/fuse-overlayfs
GraphRoot: /home/usera/.local/share/containers/storage
GraphStatus:
Backing Filesystem: xfs
Native Overlay Diff: "false"
Supports d_type: "true"
Using metacopy: "false"
ImageStore:
number: 7
RunRoot: /run/user/2229
VolumePath: /home/usera/.local/share/containers/storage/volumes
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Wednesday, October 6, 2021 11:05 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com>; Leon N <leon9923@gmail.com> *Cc:* podman mailing list <podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
What Filesystem is stored on /opt an d/nexus-data
Did you install storage in a different path then /var/lib/containers/storage.
I guess attaching podman info output would help.
On 10/6/21 10:50, Christopher.Miller@gd-ms.com wrote:
Here is my SELinux output both from the host and container. I’m getting a lot “?” characters on the host, when I think I should be seeing the user, role and type label defined. I’ve googled around based on those results and not finding anything.
I’ve tried to restorecon -R -v on those volumes and nothing changed.
Volume Mounts
host: /opt/nexus
container: /nexus-data
host: /data/storage
container: /storage
From the host
[usera@hosta /]$ sudo ls -alZ /opt/nexus
[sudo] password for usera:
total 24
drwxr-x--- 15 755 nexus ? 254 Oct 5 14:48 .
drwxr-xr-x. 13 nexus nexus system_u:object_r:usr_t:s0 214 Oct 4 10:13 ..
drwxr-xr-x 3 root root ? 21 Oct 4 10:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 14:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 10:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 11:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 14:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 10:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 10:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 10:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 14:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 10:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 14:48 lock
drwxr-xr-x 4 root root ? 220 Oct 5 20:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 14:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 10:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 14:48 tmp
[usera@hosta /]$ sudo ls -alZ /data/storage
total 24
drwxr-xr-x 2 200 200 ? 172 Oct 5 13:00 .
drwxr-x--- 3 nexus nexus ? 21 Aug 26 13:41 ..
-rw-r----- 1 root root ? 1992 Oct 5 13:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 13:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 12:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 13:00 nexus-hosta_server_crt.cer
-rw-r----- 1 root root ? 1302 Oct 5 13:00 ROOTCA-CORP.cer
From the container
[root@6ca25b429eb1 /]# sestatus
bash: sestatus: command not found
[root@6ca25b429eb1 /]# whereis selinux
selinux: /etc/selinux /usr/libexec/selinux
[root@6ca25b429eb1 /]# ls -al /etc/selinux
total 4
drwxr-xr-x 1 root root 6 Oct 6 13:49 .
drwxr-xr-x 1 root root 21 Mar 4 2021 ..
-rw-r--r-- 1 root root 2425 Jun 29 2020 semanage.conf
[root@6ca25b429eb1 /]# ls -alZ /nexus-data
total 24
drwxr-x--- 15 755 1005 ? 254 Oct 5 18:48 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
drwxr-xr-x 3 root root ? 21 Oct 4 14:37 blobs
drwxr-xr-x 323 root root ? 8192 Oct 5 18:48 cache
drwxr-xr-x 6 root root ? 113 Oct 4 14:37 db
drwxr-xr-x 3 root root ? 36 Oct 4 15:11 elasticsearch
drwxr-xr-x 3 root root ? 45 Oct 5 18:30 etc
drwxr-xr-x 2 root root ? 6 Oct 4 14:36 generated-bundles
drwxr-xr-x 2 root root ? 33 Oct 4 14:36 instances
drwxr-xr-x 3 root root ? 19 Oct 4 14:36 javaprefs
-rw-r--r-- 1 root root ? 1 Oct 5 18:48 karaf.pid
drwxr-xr-x 3 root root ? 18 Oct 4 14:37 keystores
-rw-r--r-- 1 root root ? 14 Oct 5 18:48 lock
drwxr-xr-x 4 root root ? 220 Oct 6 00:00 log
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 orient
-rw-r--r-- 1 root root ? 5 Oct 5 18:48 port
drwxr-xr-x 2 root root ? 6 Oct 4 14:37 restore-from-backup
drwxr-xr-x 8 root root ? 261 Oct 5 18:48 tmp
[root@6ca25b429eb1 /]# ls -laZ /storage
total 24
drwxr-xr-x 2 nexus nexus ? 172 Oct 5 17:00 .
drwxr-xr-x 1 root root ? 77 Oct 5 14:12 ..
-rw-r----- 1 root root ? 1992 Oct 5 17:00 ISSUINGCA-CORP_intermediate_cert.cer
-rw-r----- 1 root root ? 1302 Oct 5 17:00 ROOTCA-CORP.cer
-rw-r--r-- 1 root root ? 6582 Oct 5 17:03 nexus-hosta.enclave.jks
-rw-r--r-- 1 root root ? 1221 Oct 5 16:42 nexus-hosta.enclave.pem
-rw-r----- 1 root root ? 2532 Oct 5 17:00 nexus-hosta_server_crt.cer
Thanks again
*From:* Leon N <leon9923@gmail.com> <mailto:leon9923@gmail.com> *Sent:* Wednesday, October 6, 2021 8:29 AM *To:* Miller, Christopher (NE) <Christopher.Miller@gd-ms.com> <mailto:Christopher.Miller@gd-ms.com> *Cc:* dwalsh@redhat.com; podman mailing list <podman@lists.podman.io> <mailto:podman@lists.podman.io> *Subject:* Re: [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
*External E-mail *--- CAUTION: This email originated from outside GDMS. Do not click links or open attachments unless you recognize the sender and know the content is safe.
Hey,
These would be run on the host
You can also change the restorecon parameters to restore the contexts for the storage you mounted
sudo restorecon -R -v <path to storage>
Doing
ls -laZ on the storage you mount in the container, will also give everyone here insights on the selinux contexts
Regards,
Leon
On Wed, 6 Oct, 2021, 17:43 Christopher.Miller@gd-ms.com, <Christopher.Miller@gd-ms.com> wrote:
Sorry I’m not clear where I want to run these commands, on the host or the container?
thanks
*From:* Daniel Walsh <dwalsh@redhat.com> *Sent:* Tuesday, October 5, 2021 7:10 PM *To:* podman@lists.podman.io *Subject:* [Podman] Re: permissions issues to host filesystem when running rootless Vs rootful and question on opening port on container/host
I am guessing this is an SELinux issue. Perhaps sudo restorecon -R -v /var/lib/containers
Might fix it.
You can run `sudo ausearch -m avc -ts recent`
After it fails to see if SELinux is involved.
_______________________________________________ Podman mailing list -- podman@lists.podman.io To unsubscribe send an email to podman-leave@lists.podman.io
participants (3)
-
Christopher.Miller@gd-ms.com -
Daniel Walsh -
Leon N