Commit 42d56acf6e

42d56acf6e62f5714c9e01568bcdbaa750a60515

parent: 41f52e0d70

Verified · cmc

cmc <hello@cleberg.net> · 2026-09-07 01:26 UTC

deploy: no default sysctls in build containers

ProtectKernelTunables makes /proc/sys read-only, and podman's default
net.ipv4.ping_group_range sysctl then fails the container start. A build
has no use for ping.

Ref #144

Layout: unified · split

deploy/runner-podman-setup.sh +11
@@ -73,6 +73,17 @@ printf '[storage]\ndriver = "overlay"\ngraphroot = "%s/.local/share/containers/s
7373chown "$RUNNER_USER:$RUNNER_USER" "$conf"
7474echo " written"
7575
76# podman sets net.ipv4.ping_group_range in every container by default,
77# for unprivileged ping. The service runs with ProtectKernelTunables, so
78# /proc/sys is read-only and crun fails to start the container with
79# "open /proc/sys/net/ipv4/ping_group_range: Read-only file system". A
80# build has no use for ping; drop the default rather than the hardening.
81cconf="$home/.config/containers/containers.conf"
82echo "==> container defaults in $cconf"
83printf '[containers]\ndefault_sysctls = []\n' >"$cconf"
84chown "$RUNNER_USER:$RUNNER_USER" "$cconf"
85echo " written"
86
7687# Lingering keeps the user's systemd session alive when nobody is logged
7788# in, which podman's pause process relies on.
7889echo "==> lingering for $RUNNER_USER"