From aec62d286296423a2f97cb376d9e11d2ea68cc8c Mon Sep 17 00:00:00 2001 From: Stefan Becker Date: Sun, 10 Nov 2019 15:07:43 +0200 Subject: docs: add workaround for --device with rootless containers Fixes #4477 Signed-off-by: Stefan Becker --- docs/source/markdown/podman-run.1.md | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'docs/source/markdown/podman-run.1.md') diff --git a/docs/source/markdown/podman-run.1.md b/docs/source/markdown/podman-run.1.md index e1177cb34..e8744de35 100644 --- a/docs/source/markdown/podman-run.1.md +++ b/docs/source/markdown/podman-run.1.md @@ -210,6 +210,10 @@ Specify the key sequence for detaching a container. Format is a single character Add a host device to the container. The format is `[:][:]` (e.g. --device=/dev/sdc:/dev/xvdc:rwm) +Note: if the user only has access rights via a group then accessing the device +from inside a rootless container will fail. The `crun` runtime offers a +workaround for this by adding the option `--annotation io.crun.keep_original_groups=1`. + **--device-read-bps**=*path* Limit read rate (bytes per second) from a device (e.g. --device-read-bps=/dev/sda:1mb) -- cgit v1.2.3-54-g00ecf