davsclaus commented on code in PR #27509:
URL: https://github.com/apache/camel/pull/27509#discussion_r4210387100


##########
test-infra/camel-test-infra-spiffe/src/main/java/org/apache/camel/test/infra/spiffe/services/SpiffeLocalContainerInfraService.java:
##########
@@ -192,11 +196,36 @@ private String generateJoinToken() {
     }
 
     private void createWorkloadEntry() {
-        long uid = new UnixSystem().getUid();
+        long uid = resolveWorkloadUid();
+        LOG.info("Registering workload entry for unix:uid:{}", uid);
         exec(server, SERVER_BIN, "entry", "create", "-parentID", 
AGENT_SPIFFE_ID, "-spiffeID", WORKLOAD_SPIFFE_ID,
                 "-selector", "unix:uid:" + uid);
     }
 
+    /**
+     * Returns the UID of this JVM process as it will appear to the SPIRE unix 
workload attestor.
+     * <p>
+     * Under rootless Podman the container's user namespace maps the host 
owner uid to container uid 0, so the agent
+     * sees the test process as uid 0 when reading {@code /proc/<pid>/status} 
through the host PID namespace. On a
+     * standard (root-owned) Docker daemon no such remapping occurs and the 
real host uid is used.
+     * <p>
+     * Rootless mode is detected via the Docker info API: Podman returns 
{@code "Rootless": true} in the JSON response
+     * (captured in {@code rawValues} since the docker-java model does not 
have a typed field for it).
+     */
+    private long resolveWorkloadUid() {
+        Info info = DockerClientFactory.instance().client().infoCmd().exec();
+        Object rootless = info.getRawValues().get("Rootless");

Review Comment:
   This covers rootless Podman. Rootless Docker also remaps the owner uid to 0, 
but I believe it advertises it via `SecurityOptions` (`name=rootless`) rather 
than a `Rootless` key. Would it be worth checking that too, e.g. 
`info.getSecurityOptions() != null && 
info.getSecurityOptions().stream().anyMatch(o -> o.contains("rootless"))`?



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to