Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/test-all.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -117,7 +117,7 @@ jobs:
run: |
sudo apt-get update && sudo apt-get install -y jq
sed 's://.*$::' test/docker-in-docker/scenarios.json \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu)' \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu, .docker_iptables_switch_at_runtime_non_root)' \
> test/docker-in-docker/scenarios.json.tmp
mv test/docker-in-docker/scenarios.json.tmp test/docker-in-docker/scenarios.json

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/test-pr-arm64.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ jobs:
run: |
sudo apt-get update && sudo apt-get install -y jq
sed 's://.*$::' test/docker-in-docker/scenarios.json \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu)' \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu, .docker_iptables_switch_at_runtime_non_root)' \
> test/docker-in-docker/scenarios.json.tmp
mv test/docker-in-docker/scenarios.json.tmp test/docker-in-docker/scenarios.json

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/test-pr.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ jobs:
run: |
sudo apt-get update && sudo apt-get install -y jq
sed 's://.*$::' test/docker-in-docker/scenarios.json \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu)' \
| jq 'del(.docker_with_default_iptables, .docker_with_default_iptables_ubuntu, .docker_iptables_switch_at_runtime_non_root)' \
> test/docker-in-docker/scenarios.json.tmp
mv test/docker-in-docker/scenarios.json.tmp test/docker-in-docker/scenarios.json

Expand All @@ -114,6 +114,7 @@ jobs:
scenario:
- docker_with_default_iptables
- docker_with_default_iptables_ubuntu
- docker_iptables_switch_at_runtime_non_root
steps:
- uses: actions/checkout@v7

Expand Down
2 changes: 1 addition & 1 deletion src/docker-in-docker/devcontainer-feature.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"id": "docker-in-docker",
"version": "4.1.2",
"version": "4.1.3",
"name": "Docker (Docker-in-Docker)",
"documentationURL": "https://github.com/devcontainers/features/tree/main/src/docker-in-docker",
"description": "Create child containers *inside* a container, independent from the host's docker instance. Installs Docker extension in the container along with needed CLIs.",
Expand Down
29 changes: 15 additions & 14 deletions src/docker-in-docker/install.sh
Original file line number Diff line number Diff line change
Expand Up @@ -982,6 +982,17 @@ DOCKER_HOST_GATEWAY_IP=${DOCKER_HOST_GATEWAY_IP}
DOCKER_DEFAULT_IP6_TABLES=${DOCKER_DEFAULT_IP6_TABLES}
EOF

tee -a /usr/local/share/docker-init.sh > /dev/null \
<< 'EOF'
sudo_if() {
if [ "$(id -u)" -ne 0 ]; then
sudo "$@"
else
"$@"
fi
}
EOF

# On Debian-based images, re-assert the iptables alternative at container start
# (only when the user opted into runtime switching via iptablesSwitchAtRuntime=true).
if [ "${IPTABLES_SWITCH_AT_RUNTIME}" = "true" ] && [ "${ADJUSTED_ID}" = "debian" ]; then
Expand All @@ -995,12 +1006,12 @@ if type iptables-legacy > /dev/null 2>&1 \
&& { grep -qE '^(ip_tables)\b' /proc/modules \
|| [ -d /sys/module/ip_tables ]; } \
&& update-alternatives --list iptables 2>/dev/null | grep -q '/usr/sbin/iptables-legacy'; then
update-alternatives --set iptables /usr/sbin/iptables-legacy || true
update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy || true
sudo_if update-alternatives --set iptables /usr/sbin/iptables-legacy || true
sudo_if update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy || true
elif type iptables-nft > /dev/null 2>&1 \
&& update-alternatives --list iptables 2>/dev/null | grep -q '/usr/sbin/iptables-nft'; then
update-alternatives --set iptables /usr/sbin/iptables-nft || true
update-alternatives --set ip6tables /usr/sbin/ip6tables-nft || true
sudo_if update-alternatives --set iptables /usr/sbin/iptables-nft || true
sudo_if update-alternatives --set ip6tables /usr/sbin/ip6tables-nft || true
fi
EOF
fi
Expand Down Expand Up @@ -1130,16 +1141,6 @@ dockerd_start="AZURE_DNS_AUTO_DETECTION=${AZURE_DNS_AUTO_DETECTION} DOCKER_DEFAU
INNEREOF
)"

sudo_if() {
COMMAND="$*"

if [ "$(id -u)" -ne 0 ]; then
sudo $COMMAND
else
$COMMAND
fi
}

retry_docker_start_count=0
docker_ok="false"

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
#!/bin/bash

set -e

# Optional: Import test library
source dev-container-features-test-lib

check "entrypoint runs as codespace" bash -c "test \"$(id -un)\" = codespace"
check "iptables uses legacy backend" bash -c "iptables --version | grep -q '(legacy)'"

# Report result
reportResults
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
FROM ubuntu:noble

RUN if id ubuntu > /dev/null 2>&1; then userdel -f -r ubuntu; fi
18 changes: 18 additions & 0 deletions test/docker-in-docker/scenarios.json
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,24 @@
},
"initializeCommand": "sudo modprobe ip_tables"
},
"docker_iptables_switch_at_runtime_non_root": {
"build": {
"dockerfile": "Dockerfile"
},
"containerUser": "codespace",
"remoteUser": "codespace",
"features": {
"common-utils": {
"username": "codespace",
"userUid": "1000",
"userGid": "1000"
},
"docker-in-docker": {
"moby": "false",
"iptablesSwitchAtRuntime": true
}
}
},
"docker_with_default_iptables": {
"image": "mcr.microsoft.com/devcontainers/base:debian",
"features": {
Expand Down
Loading