Rootless Limits

What Rootless Mode Still Cannot Do

Running without privileges has costs, and some of them fail quietly. This listing, run as l3rootless, asks for an I/O limit, starts a container on privileged port 81, then a small web server on port 33081:

Limits of rootless mode, observed (as l3rootless)Shell
docker run --rm --device-write-bps /dev/sdd:1mb alpine:3 true
docker run -d --name l3-rl-81 -p 81:8080 alpine:3 sleep 600 >/dev/null
R='HTTP/1.1 200 OK\r\nContent-Length: 15\r\n\r\nrootless hello\n'
docker run -d --name l3-rl-web -p 33081:8080 -e R="$R" alpine:3 sh -c >/dev/null \
  'while :; do printf "$R" | nc -l -p 8080; done'
sleep 5; curl -s -m 3 http://localhost:33081/ || echo "33081 fails: curl exit $?"
journalctl --user -u docker.service --since "1 min ago" -o cat | grep -m1 'TCP port \*/81'
docker rm -f l3-rl-81 >/dev/null; sleep 5; curl -s -m 3 http://localhost:33081/
Output
WARNING: Your kernel does not support BPS Block I/O write limit or the cgroup is not mounted.
  Block I/O BPS
write limit discarded.
33081 fails: curl exit 7
Listen failed for HOST TCP port */81: Permission denied
rootless hello

The limitations, as measured here and as Docker 514 's rootless documentation lists them:

A workstation or CI runner that builds images rarely hits these, and a stack like BookNest's stays within them.