Singularity version 3 container
--fakeroot option to some of the singularity 3 commands requires two things to work
- Properly configured UID and GID mappeing in
/etc/sub[ug]id. This is done by default on debian stretch (9) and buster (10) and other recent distributions.
- The aility to create a process in a user namespace. On debian, this requires setting
kernel.unprivileged_userns_clone = 1in