Skip to content

podman venue leftovers: up's docker proxy check, init's next steps, doctor's cgroup manager line #453

Description

@edgehero

Small leftovers from the podman venue round, none of them blocking:

  • pi-dispatch up's docker egress step treats an exited proxy as present. It checks docker inspect exit 0, which an exited container also returns. The podman path was fixed under podman venue: start the proxy and Valkey from pi-dispatch up and the setup wizard #430 to accept only true from {{.State.Running}} on stdout; the docker path was left unchanged there to keep it byte-identical.
  • pi-dispatch init prints docker next steps on a podman-only host (PI_BACKENDS=podman), and the podman image fix lines still mention docker save ... | podman load as an alternative.
  • doctor --live on podman reports isolation as not holding when the account has no systemd user session (linger off, a plain ssh): Podman then falls back to cgroupfs, pids.max and memory.max read max, while the static podman line says the controllers are delegated. The two lines disagree; the static one should know the cgroup manager in use.

Activity

  1. edgehero commented on Sep 28, 2026

    @edgehero
    OwnerAuthor

    Fixed in #456 (merged).

    Bounds. The bounds observation read podman info's host.cgroupControllers. That list describes the caller's own cgroup, not what is delegated to the account. It now reads the controllers delegated to user@<uid>.service, and credits bounds only where Podman actually reaches that user manager.

    Behaviour change. A worker whose PI_BACKEND_FLOOR asks for isolation now refuses to boot when no user manager runs. Before, it ran jobs whose bounds were silently unapplied. Doctor names the cause.

    Correction to the issue. The failing case is sudo -iu/su with linger off, not a plain ssh login; ssh starts the user manager.

    Also fixed:

    • up sees an exited docker egress proxy and offers to start it.
    • init prints the podman steps when podman is the only venue.
    • The podman image fix lines no longer suggest docker save | podman load.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions