I have been exploring ways to run self-hosted Bitbucket runners without requiring privileged mode (privileged: true). Specifically, I attempted to use the docker:23.0-dind-rootless image in combination with the Bitbucket runner image (docker-public.packages.atlassian.com/sox/atlassian/bitbucket-pipelines-runner) as an alternative to the docker:23.0.0-dind image. Unfortunately, this led to various errors. Additionally, I tested integrating the Kaniko image alongside the Bitbucket runner image, but encountered Java-related errors during the process.
Given this, I have the following questions:
- Is there a recommended approach to securely build container images in Bitbucket using self-hosted runners, without needing privileged mode enabled?
- Does Bitbucket officially support tools such as Kaniko or Podman to allow for daemonless builds, thus eliminating the requirement for Docker daemon root privileges?
I noticed that GitLab provides clear documentation on how to use Kaniko for secure, daemonless builds (e.g., GitLab Documentation on Kaniko), but I was unable to find similar resources within the Bitbucket community. Having detailed guidance on this topic would be extremely helpful for Bitbucket users as well.
I would greatly appreciate your guidance or any best practices for addressing this use case.
Thank you for your time and assistance