dind was privileged: true, so a job that escaped into dind was root on Veron 1, which is Grant's workstation. Under sysbox-runc (sysbox-ce 0.7.1, installed 09-23 with no docker restart) dind root is an unprivileged host uid. Smoke-tested standalone: nested containers, internet, a services-style postgres on a private network and a python image all pass unprivileged. Fresh volume dind-storage-sysbox; the old dind-storage stays for docker-compose.privileged.yml, the one-command rollback. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
16 lines
576 B
YAML
16 lines
576 B
YAML
# ROLLBACK ONLY: the pre-Sysbox dind (privileged: true), kept one command away.
|
|
# Use it if CI breaks under Sysbox:
|
|
#
|
|
# cd /srv/windygit/src/deploy/runner
|
|
# sudo docker compose -f docker-compose.yml -f docker-compose.privileged.yml up -d dind
|
|
#
|
|
# (then restart the runners while idle). Compose merges `volumes` by container
|
|
# path, so this puts back the old `dind-storage` volume with its image cache.
|
|
# Going forward again: the same command without the second -f.
|
|
services:
|
|
dind:
|
|
runtime: runc
|
|
privileged: true
|
|
volumes:
|
|
- dind-storage:/var/lib/docker
|