From c093d6a845a129bcf459167a30f7d9f2a7ff965d Mon Sep 17 00:00:00 2001 From: Chris Evich Date: Wed, 4 Oct 2023 13:49:24 -0400 Subject: [PATCH] Improve user-namespace docs slightly Try to explain in more detail and add new error-message possibility. Signed-off-by: Chris Evich --- README.md | 59 +++++++++++++++++++++++++++++++++++++++++-------------- 1 file changed, 44 insertions(+), 15 deletions(-) diff --git a/README.md b/README.md index 7f86808..c338006 100644 --- a/README.md +++ b/README.md @@ -20,6 +20,9 @@ when running potentially arbitrary CI/CD code. Though, the ultimate responsibility still rests with the end-user to review the setup and configuration relative to their own security situation/environment. +**Note**: While this can run entirely under a regular user, it will require +root access for the first two setup steps (below). + ### Operation This image leverages the podman `runlabel` feature heavily. Several @@ -42,7 +45,7 @@ $ eval $(podman inspect --format=json $IMAGE | jq -r .[].Labels.