# User namespace and the network agent container

**URL:** <https://forums.suse.com/t/user-namespace-and-the-network-agent-container/2568>\
**Category:** General\
**Created:** [April 22, 2016, 2:35pm UTC](https://forums.suse.com/t/user-namespace-and-the-network-agent-container/2568 "2016-04-22T14:35:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fraser\_Goffin](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/fraser_goffin/32/6608_2.png) [@Fraser\_Goffin](https://forums.suse.com/u/Fraser_Goffin)\
**Post date:** [April 22, 2016, 2:35pm UTC](https://forums.suse.com/t/user-namespace-and-the-network-agent-container/2568/1 "2016-04-22T14:35:52Z")

</div>

One of the new security feaures in docker 1.10.x is user namespaces. This enables container processes to run as the ‘root’ user (from the perspective of the container), but that user is mapped to a different (and by default un-privileged) account on the host. Clearly this is an important security mitigation and one which we would like to configure.

However, some containers, and amongst them the Rancher Network Agent, run as a privileged container. It appears to be possible to continue to run such containers in that mode using --userns=host for docker ‘run’, but my question is, given that this container is deployed automatically by Rancher and (at present) the --userns-remap=xxx is a daemon level setting, can Rancher Labs confirm (or otherwise) that using user namespaces is supported ?

Also, there are other limitations from using user namespaces (see: [https://docs.docker.com/engine/reference/commandline/daemon/#daemon-user-namespace-options](https://docs.docker.com/engine/reference/commandline/daemon/#daemon-user-namespace-options)), are any of these likely to be problematic in a Rancher environment ?

Kind Regards

Fraser.

---

<div class="post-metadata">

**Author:** ![demiller](https://avatars.discourse-cdn.com/v4/letter/d/49beb7/32.png) [@demiller](https://forums.suse.com/u/demiller)\
**Post date:** [June 6, 2016, 3:11pm UTC](https://forums.suse.com/t/user-namespace-and-the-network-agent-container/2568/2 "2016-06-06T15:11:08Z")

</div>

Hi Fraser - did you ever get any feedback on this issue? I am wondering the same thing.

---

<div class="post-metadata">

**Author:** ![Fraser\_Goffin](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/fraser_goffin/32/6608_2.png) [@Fraser\_Goffin](https://forums.suse.com/u/Fraser_Goffin)\
**Post date:** [June 6, 2016, 7:29pm UTC](https://forums.suse.com/t/user-namespace-and-the-network-agent-container/2568/3 "2016-06-06T19:29:38Z")

</div>

Hey Dennis,

No, no-one from Rancher has come back to me thus far. That said I will ask again thru a more direct route and report back if anything comes of that. We are about to start a security sweep of our entire docker estate so I’m sure this one is going to come up.
