Skip to content

Feature: Document SELinux bind-mount note for local devcontainer usage #1879

Description

@bowie2211

Describe the enhancement or feature you would like

When using the CPython devcontainer image on SELinux-enabled Linux hosts, a plain bind mount may fail with Permission denied inside the container.

Example:

docker run -it --rm \
  -v "$PWD:/workspace" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest

In that case, a SELinux-compatible bind mount works:

  docker run -it --rm \
  -v "$PWD:/workspace:Z" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest

Without relabeling, /workspace may not be readable from inside the container.

It may be helpful to add a short note to the local Docker/devcontainer documentation for SELinux-enabled hosts, preferably using the :Z bind-mount form.

Describe alternatives you have considered

As an alternative workaround, this also works:

docker run -it --rm \
  --security-opt label=disable \
  -v "$PWD:/workspace" \
  -w /workspace \
  ghcr.io/python/devcontainer:latest

Additional context

No response

Activity

  1. pranavchoudhary-tech commented on Aug 14, 2026

    @pranavchoudhary-tech
    Contributor

    I'd be happy to handle this. I will submit a PR adding the SELinux bind-mount note to the devcontainer documentation.

  2. Anusha27-08 commented on Oct 9, 2026

    @Anusha27-08
  3. Poojabala30 commented on Oct 10, 2026

    @Poojabala30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-featureAdditions; New content or section needed

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions