Skip to content
This repository has been archived by the owner on Mar 20, 2023. It is now read-only.

Run benefice workloads via rootless OCI engine #131

Open
rvolosatovs opened this issue Aug 31, 2022 · 0 comments
Open

Run benefice workloads via rootless OCI engine #131

rvolosatovs opened this issue Aug 31, 2022 · 0 comments
Assignees

Comments

@rvolosatovs
Copy link
Member

Currently, Benefice workloads are executed via Docker, which means that they're essentially executed as root (and benefice user also has privileged access to the system, since it has to be in docker group)
Naturally, we want to avoid this and using podman could be a way to do that. Unfortunately I was unable to make podman work for this use case with TEEs, on SGX I'd get "OCI permission denied" on AESMD socket and SEV execution would fail with "system miconfigured" reported by Enarx. Refs profianinc/nixpkgs#18

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
Status: New
Development

No branches or pull requests

2 participants