Run nested containers in workspaces
You can enable container run capabilities in Che workspaces to allow running nested containers by using tools such as Podman. This feature leverages Linux kernel user namespaces for isolation, so that users can build and run container images within their workspaces.
|
Previously created workspaces cannot be started after enabling this feature. Users will need to create new workspaces. |
|
Prerequisites
-
An active
kubectlsession with administrative permissions to the destination Kubernetes cluster. See Overview of kubectl. -
An instance of Che running in Kubernetes.
Procedure
-
Configure the
CheClustercustom resource to enable container run capabilities:kubectl patch checluster/eclipse-che -n eclipse-che \ --type='merge' -p \ '{"spec":{"devEnvironments":{"disableContainerRunCapabilities":false}}}'
Additional resources