You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
podman venue leftovers: up's docker proxy check, init's next steps, doctor's cgroup manager line #453
Small leftovers from the podman venue round, none of them blocking:
pi-dispatch up's docker egress step treats an exited proxy as present. It checks docker inspect exit 0, which an exited container also returns. The podman path was fixed under podman venue: start the proxy and Valkey from pi-dispatch up and the setup wizard #430 to accept only true from {{.State.Running}} on stdout; the docker path was left unchanged there to keep it byte-identical.
pi-dispatch init prints docker next steps on a podman-only host (PI_BACKENDS=podman), and the podman image fix lines still mention docker save ... | podman load as an alternative.
doctor --live on podman reports isolation as not holding when the account has no systemd user session (linger off, a plain ssh): Podman then falls back to cgroupfs, pids.max and memory.max read max, while the static podman line says the controllers are delegated. The two lines disagree; the static one should know the cgroup manager in use.
Bounds. The bounds observation read podman info's host.cgroupControllers. That list describes the caller's own cgroup, not what is delegated to the account. It now reads the controllers delegated to user@<uid>.service, and credits bounds only where Podman actually reaches that user manager.
Behaviour change. A worker whose PI_BACKEND_FLOOR asks for isolation now refuses to boot when no user manager runs. Before, it ran jobs whose bounds were silently unapplied. Doctor names the cause.
Correction to the issue. The failing case is sudo -iu/su with linger off, not a plain ssh login; ssh starts the user manager.
Also fixed:
up sees an exited docker egress proxy and offers to start it.
init prints the podman steps when podman is the only venue.
The podman image fix lines no longer suggest docker save | podman load.
Small leftovers from the podman venue round, none of them blocking:
pi-dispatch up's docker egress step treats an exited proxy as present. It checksdocker inspectexit 0, which an exited container also returns. The podman path was fixed under podman venue: start the proxy and Valkey from pi-dispatch up and the setup wizard #430 to accept onlytruefrom{{.State.Running}}on stdout; the docker path was left unchanged there to keep it byte-identical.pi-dispatch initprints docker next steps on a podman-only host (PI_BACKENDS=podman), and the podman image fix lines still mentiondocker save ... | podman loadas an alternative.doctor --liveon podman reportsisolationas not holding when the account has no systemd user session (linger off, a plainssh): Podman then falls back to cgroupfs,pids.maxandmemory.maxreadmax, while the static podman line says the controllers are delegated. The two lines disagree; the static one should know the cgroup manager in use.