Q: Your security compliance mandate requires that no developers or automated CI jobs have root access to host operating systems. Previously, adding developers to the `docker` group effectively granted them full passwordless root access (`docker run -v /:/host alpine`). You must migrate all developer bastion servers and multi-tenant CI workers to Rootless Docker and rootless containerd, ensuring that even if a container suffers a complete runtime escape, the attacker only gains an unprivileged UID on the host.
Deploy, configure, and secure Rootless Docker and containerd daemons. Understand user namespaces (`userns`), UID/GID sub-allocations, rootless networking with slirp4netns/pasta, and rootless limitations.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Configure SubUID and SubGID Sub-Allocations
Rootless mode requires mapping user namespaces. Allocate subordinate UIDs and GIDs for unprivileged developers in `/etc/subuid` and `/etc/subgid`.
# Check subordinate UID and GID ranges for user 'devuser'
echo "devuser:100000:65536" | sudo tee -a /etc/subuid
echo "devuser:100000:65536" | sudo tee -a /etc/subgid
# Verify user mappings
grep devuser /etc/subuid /etc/subgid
Install and Start Rootless Docker via systemd User Session
Install the rootless Docker package and initialize the systemd user daemon using `dockerd-rootless-setuptool.sh` without sudo.
# Switch to non-root developer account
su - devuser
# Install rootless docker
dockerd-rootless-setuptool.sh install
# Enable lingering so daemon runs when user logs out
loginctl enable-linger devuser
# Export Docker daemon environment socket
export DOCKER_HOST=unix:///run/user/$(id -u)/docker.sock
echo 'export DOCKER_HOST=unix:///run/user/$(id -u)/docker.sock' >> ~/.bashrc
# Verify rootless docker daemon status
systemctl --user status docker
Evaluate Rootless Network Drivers: slirp4netns vs pasta
By default, rootless containers cannot configure standard kernel bridge devices because creating network namespaces and veth pairs requires `CAP_NET_ADMIN`. Rootless Docker uses user-mode network stacks: `slirp4netns` or the faster `pasta` (from passt project).
# Configure dockerd rootless options in ~/.config/docker/daemon.json
cat <<EOF > ~/.config/docker/daemon.json
{
"dns": ["8.8.8.8", "1.1.1.1"],
"rootless-net-driver": "pasta"
}
EOF
systemctl --user restart docker
Validate Container Escape Confinement
Test breakout isolation. Spawn a container running as root (`UID 0`), and verify that on the host kernel it maps strictly to unprivileged UID 100000.
# Run container as 'root'
docker run -d --name test-escape alpine sleep 3600
# Inspect host PID and mapped UID
HOST_PID=$(docker inspect test-escape --format '{{.State.Pid}}')
ps -fp $HOST_PID -o pid,user,uid,comm
# Output confirms UID is 100000 (unprivileged subuid on host)
- A
- d
- d
- i
- n
- g
- d
- e
- v
- e
- l
- o
- p
- e
- r
- s
- t
- o
- t
- h
- e
- `
- d
- o
- c
- k
- e
- r
- `
- g
- r
- o
- u
- p
- i
- s
- e
- q
- u
- i
- v
- a
- l
- e
- n
- t
- t
- o
- g
- r
- a
- n
- t
- i
- n
- g
- p
- a
- s
- s
- w
- o
- r
- d
- l
- e
- s
- s
- h
- o
- s
- t
- r
- o
- o
- t
- .
- W
- e
- m
- i
- t
- i
- g
- a
- t
- e
- d
- t
- h
- i
- s
- p
- r
- i
- v
- i
- l
- e
- g
- e
- e
- s
- c
- a
- l
- a
- t
- i
- o
- n
- v
- e
- c
- t
- o
- r
- b
- y
- d
- e
- p
- l
- o
- y
- i
- n
- g
- R
- o
- o
- t
- l
- e
- s
- s
- D
- o
- c
- k
- e
- r
- a
- c
- r
- o
- s
- s
- a
- l
- l
- d
- e
- v
- e
- l
- o
- p
- m
- e
- n
- t
- n
- o
- d
- e
- s
- .
- B
- o
- t
- h
- t
- h
- e
- d
- a
- e
- m
- o
- n
- a
- n
- d
- c
- o
- n
- t
- a
- i
- n
- e
- r
- s
- r
- u
- n
- s
- t
- r
- i
- c
- t
- l
- y
- w
- i
- t
- h
- i
- n
- u
- n
- p
- r
- i
- v
- i
- l
- e
- g
- e
- d
- u
- s
- e
- r
- n
- a
- m
- e
- s
- p
- a
- c
- e
- s
- ,
- g
- u
- a
- r
- a
- n
- t
- e
- e
- i
- n
- g
- t
- h
- a
- t
- a
- n
- y
- c
- o
- n
- t
- a
- i
- n
- e
- r
- b
- r
- e
- a
- k
- o
- u
- t
- y
- i
- e
- l
- d
- s
- z
- e
- r
- o
- h
- o
- s
- t
- p
- r
- i
- v
- i
- l
- e
- g
- e
- s
- .