2025-12-17 09:21 UTC
docker run --rm -it --privileged --pid=host debian:12 nsenter -a -t1 "$(which bash)"
If your user is in the docker group, and you are not running rootless Docker, this command opens a bash shell as root.
How it works:
docker run --rm -it creates a temporary container and attaches it to the running terminal
--privileged disables some of the container’s protections
--pid=host attaches the container to the host’s PID namespace, allowing it to access all running processes
debian:12 uses the Debian 12 image
nsenter -a -t1 enters all the namespaces of the process with PID 1, which is the host’s init since we use --pid=host
"$(which bash)" finds the path of the host’s bash and runs it inside the namespaces (plain bash may not work on NixOS hosts)
Replies (1)
-
@noughtnaut@lemmy.world 2025-12-17 21:09
So you’re running bash “as if you’re on the host systen”. What’s the benefit?