Skip to content

Securely share project directory with LXD guest for write #32

Description

@abitrolly

Problem

lxd-runin.sh mounts current directory read-only.

The official way to share host dirs with containers is to use disk device.

$ lxc config device add <container> <sharename> disk source="$PWD" \
 path="/root/$(basename "$PWD")"

And that makes all files inside container owned by nobody:nobody. The issue is described at lxc/incus#2025 and the solution is to direct kernel to map uid/gid of user from host to uid/gid of user from guest (which is root in this case).

The proposed solution raises a security issue - if container process with mapped uid/gid escapes filesystem boundaries, it will be able to steal private keys of host user. Secure solution is to rewrite file owner on filesystem access layer without touching container gid/uid.

Solution 1 - Patch LXD

The logical way is to add another device called dir-proxy to LXD that will do the necessary conversion. It requires knowledge of LXD and may not be feasible, because LXD is a wrapper over standard Linux containers and may be limited to what containers are capable of.

Solution 2 - Use 9p server on host and access it with FUSE client on guest

While kernel has support for 9p filesystem, it won't allow to mount it from unprivileged container. Other FUSE clients don't have this limitation. An additional benefit will be the ability to mount local project dir to remote LXD container (#26) provided that there is a secure channel between guest and host (LXD proxy devices?).

I am looking to add these features to lxd-runin.sh script. The stumbling block right now is to find a binary for 9p client that will provide FUSE server and could be easily injected in remote container.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions