mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 03:13:16 +00:00
docs(webtop): abc can use docker without sudo
The universal-docker mod adds abc to the socket's group before the desktop starts as abc.
This commit is contained in:
1 parent
bfd9fdbfd3
commit
09506ae84f
1 file changed
+5
-2
+5
-2
@@ -43,8 +43,11 @@ inside are siblings on the host, not children: bind mounts in them resolve
|
||||
against host paths, so a path under `/config` will not exist unless the same
|
||||
path exists on the host.
|
||||
|
||||
The socket belongs to the host's `docker` group, which `abc` is not in; run
|
||||
`docker` under `sudo` (the password is `PASSWORD`). Handing a container the
|
||||
The socket belongs to the host's `docker` group. At startup the mod reads the
|
||||
socket's GID, creates a group with it if none exists and adds `abc` to it. The
|
||||
desktop starts as `abc` afterwards, with that group, so `docker` works without
|
||||
`sudo` in any terminal it opens. `CUSTOM_USER` only names the web login; the
|
||||
Linux user is still `abc`. Handing a container the
|
||||
socket is equivalent to giving it root on the host, accepted here because this
|
||||
is a single-user desktop. The `:ro` flag only marks the socket file read-only;
|
||||
it does not restrict the Docker API.
|
||||
|
||||
Reference in new issue
Block a user