Update rootfs.md: Fix formatting and wording of idmap option

The newly introduced `idmap` section of rootfs lacked a header
(comparable to Overlay Rootfs Mounts), had odd formatting, and
wording that differed from other instances of idmap, e.g., the
one in the --volume section. This commits addresses those issues.

Signed-off-by: Peter Whittaker <PeterWhittaker@SphyrnaSecurity.com>
This commit is contained in:
Peter Whittaker 2023-08-14 09:21:24 -04:00
parent 0b612a9a2d
commit 345b9b0295
1 changed files with 3 additions and 1 deletions

View File

@ -22,7 +22,9 @@ finishes executing, similar to a tmpfs mount point being unmounted.
Note: On **SELinux** systems, the rootfs needs the correct label, which is by default
**unconfined_u:object_r:container_file_t:s0**.
The `idmap` option if specified, creates an idmapped mount to the target user
`idmap`
If `idmap` is specified, create an idmapped mount to the target user
namespace in the container.
The idmap option supports a custom mapping that can be different than the user
namespace used by the container. The mapping can be specified after the idmap