# Linux user mapping in Kubernetes with containerd

**URL:** <https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468>\
**Category:** General Discussions\
**Tags:** development\
**Created:** [June 29, 2022, 2:28pm UTC](https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468 "2022-06-29T14:28:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![DeDze](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/dedze/32/10353_2.png) [@DeDze](https://discuss.kubernetes.io/u/DeDze)\
**Post date:** [June 29, 2022, 2:28pm UTC](https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468/1 "2022-06-29T14:28:16Z")

</div>

I have a question about how kubernetes maps the host users with the containers’ usernamespace user.

Basically, when I create a securityContext with runAsUser set to a uid which exists in the host usernamespace, I can see in the host `ps -aux` output that the process is started with this specific uid (and therefore the same username). This leads to weird things such as sshd running sleep command when I pass runAsUser: 106 in the pod securityContext.  
[sshdSleepingImage](https://i.stack.imgur.com/5gprH.png)

Therefore, I think that Kubernetes (or containerd ?) maps the host uid 106 to the container usernamespace userid 106. Is it the expected behaviour?

Wouldn’t it be more logical to map the nobody user of the host (or at least an other user or uid) with the user in the container usernamespace?

Thanks in advance for the answers

---

<div class="post-metadata">

**Author:** ![thockin](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/thockin/32/2457_2.png) [@thockin](https://discuss.kubernetes.io/u/thockin)\
**Post date:** [June 29, 2022, 3:06pm UTC](https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468/2 "2022-06-29T15:06:18Z")

</div>

There’s a KEP in progress to add users to k8s. It’s not as simple as just mapping to nobody, though.

---

<div class="post-metadata">

**Author:** ![DeDze](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/dedze/32/10353_2.png) [@DeDze](https://discuss.kubernetes.io/u/DeDze)\
**Post date:** [June 29, 2022, 3:32pm UTC](https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468/3 "2022-06-29T15:32:02Z")

</div>

Thank you for the answer.

Why isn’t it a solution to map the nobody user (or an other created user for this purpose) to the user in the container namespace if we don’t want privileged containers ?

---

<div class="post-metadata">

**Author:** ![thockin](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/thockin/32/2457_2.png) [@thockin](https://discuss.kubernetes.io/u/thockin)\
**Post date:** [June 30, 2022, 4:53pm UTC](https://discuss.kubernetes.io/t/linux-user-mapping-in-kubernetes-with-containerd/20468/4 "2022-06-30T16:53:41Z")

</div>

I invite you to review the KEP, and if you want more details, you can read the PR history of it 🙂

[https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/127-user-namespaces](https://github.com/kubernetes/enhancements/tree/master/keps/sig-node/127-user-namespaces)
