From 09506ae84fa2a5426fe36b910a27811c2614bc75 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Tue, 6 Oct 2026 17:22:20 +0700 Subject: [PATCH] docs(webtop): abc can use docker without sudo The universal-docker mod adds abc to the socket's group before the desktop starts as abc. --- webtop/README.md | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/webtop/README.md b/webtop/README.md index 07dbc18..db54749 100644 --- a/webtop/README.md +++ b/webtop/README.md @@ -43,8 +43,11 @@ inside are siblings on the host, not children: bind mounts in them resolve against host paths, so a path under `/config` will not exist unless the same path exists on the host. -The socket belongs to the host's `docker` group, which `abc` is not in; run -`docker` under `sudo` (the password is `PASSWORD`). Handing a container the +The socket belongs to the host's `docker` group. At startup the mod reads the +socket's GID, creates a group with it if none exists and adds `abc` to it. The +desktop starts as `abc` afterwards, with that group, so `docker` works without +`sudo` in any terminal it opens. `CUSTOM_USER` only names the web login; the +Linux user is still `abc`. Handing a container the socket is equivalent to giving it root on the host, accepted here because this is a single-user desktop. The `:ro` flag only marks the socket file read-only; it does not restrict the Docker API.