Why ypou happy they suffer?
- 1 Post
- 7 Comments
Joined 3 years ago
Cake day: June 20th, 2023
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
HappyFrog@lemmy.blahaj.zoneto
Lefty Memes@lemmy.dbzer0.com•When everyone is super, no one will beEnglish
0·9 days agoWhat? We have commie leaders? Who? Where?
I like that you can see the wheel missing in panel 2 and 3
HappyFrog@lemmy.blahaj.zoneto
You Should Know@lemmy.world•YSK a US passport card costs $30 and is definitive proof of citizenship. It fits in your wallet like a credit card.
0·13 days agoAh, so you are trying to get people killed.
HappyFrog@lemmy.blahaj.zoneto
You Should Know@lemmy.world•YSK a US passport card costs $30 and is definitive proof of citizenship. It fits in your wallet like a credit card.
01·13 days agoAre you actively encouraging people to not seek protections against a fascist regime just because it wouldn’t be 100% effective?
HappyFrog@lemmy.blahaj.zoneto
You Should Know@lemmy.world•YSK a US passport card costs $30 and is definitive proof of citizenship. It fits in your wallet like a credit card.
0·13 days agoYeah, but you’re at least a little more likely to survive.

I don’t know much about ip routing, but userns=keep-id id determined based on what podman is run as. For example, I run podman as user 1000 on the host, so if I do keep-id the user in the container will map to the same id. This often messes with things as the container require it is root inside it’s own context. It seems you are running podman as root, meaning that keep-id will map the container user to the actual root id, givintthe container essentially root access. Normally the container user is mapped to a random id on the host, like 653477, not 0. It’s unsafe to map the containers id to root as they would be unbounded if they managed to escape. I would recommend doing
systemctl caton the different services to see what the .container file expands to.When it comes to the networking I think that you need to create a podman network with internal set to true. I believe that this restricts internet access. Then you would need to only let these services communicate with gluetun.
I don’t know if this was any help, but it’s all I’ve managed to learn from doing it myself.
Here are some liks I found:
https://lists.podman.io/archives/list/podman@lists.podman.io/thread/NKVFO4JQO5JLYKWXHHODC2WHQRG7A2KO/
https://docs.podman.io/en/v4.6.1/markdown/options/userns.container.html