Giving the user inside a container permission on a device

Viewed 248

I have a container that's based on the matspfeiffer/flutter image. I'm trying to forward some of my devices present on my host to the container so eventually I can run an android emulator from inside it.

I'm providing the following options to the docker run command:

--device /dev/kvm
--device /dev/dri:/dev/dri
-v /tmp/.X11-unix:/tmp/.X11-unix
-e DISPLAY

This renders the /dev/kvm device accessible from within the container.

However, the permissions for the /dev/kvm device on my host are the following:

crw-rw----+ 1 root kvm 10, 232 oct.   5 19:12 /dev/kvm

So from within the container I'm unable to interact with the device properly because of insufficient permissions.

My best shot at fixing the issue so far has been to alter the permissions of the device on my host machine like so:

sudo chmod 777 /dev/klm

It fixes the issue but it goes without saying that it is not in any case an appropriate solution.

I was wondering if there was a way to grant the container permission to interact with that specific device without altering the permissions on my host.

I am open to giving --privileged access to my host to my container.

I also wish to be able to create files from within the container without the permissions being messed up (I was once root inside a Docker container which made it so every file I would create in a shared volume from within the container inaccessible from my host).

For reference, I'm using VS Code remote containers to build and run the container so the complete docker run command as provided by VS Code is the following

docker run --sig-proxy=false -a STDOUT -a STDERR --mount type=bind,source=/home/diego/Code/Epitech/B5/redditech,target=/workspaces/redditech --mount type=volume,src=vscode,dst=/vscode -l vsch.local.folder=/home/diego/Code/Epitech/B5/redditech -l vsch.quality=stable -l vsch.remote.devPort=0 --device /dev/kvm --device /dev/dri:/dev/dri -v /tmp/.X11-unix:/tmp/.X11-unix -e DISPLAY --fifheri --entrypoint /bin/sh vsc-redditech-850ec704cd6ff6a7a247e31da931a3fb-uid -c echo Container started
0 Answers
Related