Commit graph

14255 commits

Author SHA1 Message Date
Daniel J Walsh
ee7cf3cc2c Don't log errors on removing volumes inuse, if container --volumes-from
When removing a container created with a --volumes-from a container
created with a built in volume, we complain if the original container
still exists.  Since this is an expected state, we should not complain
about it.

Fixes: https://github.com/containers/podman/issues/12808

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2022-02-23 14:27:52 -05:00
Giuseppe Scrivano
eb9fe52a55 kube: honor mount propagation mode
convert the propagation mode specified for the mount to the expected
Linux mount option.

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2022-02-23 14:26:10 -05:00
Paul Holzinger
a0c34d64a5 Load ip_tables modules at boot
Rootless users cannot load the ip_tables module, in fedora 36 this
module is no longer loaded by default so we have to add it manually.
This is needed because rootless network setup tries to use iptables
and if iptables-legacy is used instead of iptables-nft it will fail.

To provide a better user experience we will load the module at boot.

Note that this is not needed for RHEL because iptables-legacy is not
supported on RHEL 8 and newer.

[NO NEW TESTS NEEDED]

Fixes #12661

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-02-23 14:25:09 -05:00
OpenShift Merge Robot
172b745d0e
Merge pull request #13251 from cevich/new_4.0_vm_images
[v4.0] Cirrus: Update VM Images for 4.0 release
2022-02-19 22:51:31 -05:00
Chris Evich
e8d7e580a9
Cirrus: Disable F34 aka prior-fedora testing
Podman 4.0 will never be supported in F34, and the use of F35 in CI is
temporary until F36 is brought up to speed.  Rather than fight with
testing issues that will never be fixed/supported, simply disable it.
This commit may be reverted at a future date when F36 VM support is
added.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-17 16:37:48 -05:00
Chris Evich
7b106f5b6b
Cirrus: Update VM Images for 4.0 release
This is to ensure VM images for CI, which contain the
intended dependency versions to support the podman
4.0 release.

Ref: https://github.com/containers/automation_images/pull/114

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-17 16:37:06 -05:00
OpenShift Merge Robot
93e8c39834
Merge pull request #13255 from mheon/bump_400_final
Bump to v4.0.0 final
2022-02-17 14:26:39 -05:00
Matthew Heon
d59749d64d Bump to v4.0.1-dev
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-17 12:34:05 -05:00
Matthew Heon
49f8da7271 Bump to v4.0.0
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-17 12:34:05 -05:00
Matthew Heon
84c8870ac2 Release notes for v4.0.0 final
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-17 12:34:05 -05:00
Matthew Heon
15cb918556 Fix lint
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-17 12:34:05 -05:00
Jhon Honce
ae9ad416a3 Fix manifest 4.0 Endpoints
Branch forced 4.0 only endpoints

Signed-off-by: Jhon Honce <jhonce@redhat.com>
2022-02-17 12:34:05 -05:00
Jason T. Greene
1a8c715f1f Introduce podman machine init --root=t|f and podman machine set --root=t|f
Switch default to rootless for mac and windows

Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
2022-02-16 14:02:58 -05:00
Jason T. Greene
f71dfcb5da Initial implementation of mac forwarding using a privileged docker sock claim helper
Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
2022-02-16 14:02:52 -05:00
esendjer
2128236da5 ignition: propagate proxy settings from a host into a vm
Set proxy settings (such as `HTTP_PROXY`, and others)
for the whole guest OS with setting up `DefaultEnvironment`
with a `systemd` configuration file `default-env.conf`,
a `profile.d` scenario file - `default-env.sh` and
a `environment.d` configuration file `default-env.conf`

The **actual** environment variables are read by podman
at a start, then they are encrypted with base64 into
a single string and after are provided into a VM through
QEMU Firmware Configuration (fw_cfg) Device

Inside a VM a systemd service `envset-fwcfg.service`
reads the providead encrypted string from fw_cfg, decrypts
and then adds to the files
 - `/etc/systemd/system.conf.d/default-env.conf`
 - `/etc/profile.d/default-env.sh`
 - `/etc/environment.d/default-env.conf`
At the end this service execute  `systemctl daemon-reload`
to propagate new variables for systemd manager

[NO NEW TESTS NEEDED]

Closes #13168

Signed-off-by: esendjer <esendjer@gmail.com>
2022-02-16 14:02:42 -05:00
Jason T. Greene
809da6b0ba Update to podman4 copr stream
Signed-off-by: Jason T. Greene <jason.greene@redhat.com>
2022-02-16 14:01:20 -05:00
Patrycja Guzik
bd8ac0017e Unify ls --filter docs for networks and pods
Signed-off-by: Patrycja Guzik <patrycja.k.guzik@gmail.com>

#13078 follow-up
2022-02-16 14:00:50 -05:00
Valentin Rothberg
77e51e188c e2e: merge after/since image-filter tests
Merge the two tests to speed up testing.  Both built the exact same
images.

Signed-off-by: Valentin Rothberg <vrothberg@redhat.com>
2022-02-16 14:00:30 -05:00
Paul Holzinger
8ad29421eb podman network: add documentation for netavark
Add some docs about the different network backends. Also remove the CNI
word from network since we refer to either a netavark or CNI config.

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-02-16 14:00:06 -05:00
Morten Linderud
f35e03ec81 create: Fix key=value annotation in the flag output
[NO NEW TESTS NEEDED]

Signed-off-by: Morten Linderud <morten@linderud.pw>
2022-02-16 13:59:36 -05:00
Lokesh Mandvekar
22cfa98605 enable netavark specific tests
These are copies of the CNI tests with modifications wherever
neccessary.

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2022-02-16 13:59:04 -05:00
Adrian Reber
d77b4f92c0 Fix checkpoint/restore pod tests
Checkpoint/restore pod tests are not running with an older runc and now
that runc 1.1.0 appears in the repositories it was detected that the
tests were failing. This was not detected in CI as CI was not using runc
1.1.0 yet.

Signed-off-by: Adrian Reber <areber@redhat.com>
2022-02-16 13:58:40 -05:00
Daniel J Walsh
a72e22160a Make sure building with relative paths work correctly.
Fixes: https://github.com/containers/podman/issues/12763

Signed-off-by: Daniel J Walsh <dwalsh@redhat.com>
2022-02-16 13:56:39 -05:00
Jhon Honce
975d79aedb Add 409 response to swagger godoc
When attempting to create a network with a name that already exists,
a 409 status code will be returned

[NO NEW TESTS NEEDED]

Signed-off-by: Jhon Honce <jhonce@redhat.com>
2022-02-16 13:55:56 -05:00
OpenShift Merge Robot
a34f27959a
Merge pull request #13233 from baude/v4.0fcosside
[BACKPORT] V4.0fcosside
2022-02-16 13:27:44 -05:00
Brent Baude
421b7466c2 Fix images since/after tests
For the since and after imagve filter tests, instead of using the
read-only cache of images, we just use the empty r/w store.  We then
build three images that are strictly predictable.

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-16 10:49:43 -06:00
Brent Baude
04badc2c9c Changes of docker descriptions
It looks like some descriptions have changed on the docker registry
where we had been searching for images that include 'alpine'.  We are
now seeing an image in the initial list that has 'alpine' in its
description.

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-16 10:49:35 -06:00
OpenShift Merge Robot
aa1a6b6eaa
Merge pull request #13249 from baude/backporte2efixes
[BACKPORT] Backporte2efixes
2022-02-16 11:33:43 -05:00
Brent Baude
09708bee9c Fix images since/after tests
For the since and after imagve filter tests, instead of using the
read-only cache of images, we just use the empty r/w store.  We then
build three images that are strictly predictable.

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-16 08:55:36 -06:00
Brent Baude
35a4f32be6 Changes of docker descriptions
It looks like some descriptions have changed on the docker registry
where we had been searching for images that include 'alpine'.  We are
now seeing an image in the initial list that has 'alpine' in its
description.

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-16 08:38:50 -06:00
Brent Baude
629d864459 Temporarily pull machine images from side repo
Until podman4 is in the fcos trees, we need to pull the machine images
from a side repository.  There is a hard coded bit that forces the
side repo download right now.  Simple comment or removal of the bit will
revert to normal download behavior.

[NO NEW TESTS NEEDED]

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-14 15:10:40 -06:00
OpenShift Merge Robot
ab3e566d74
Merge pull request #13216 from cevich/ci_updates
[4.0] Enable Netavark/Aardvark-DNS CI Testing
2022-02-14 08:28:37 -05:00
OpenShift Merge Robot
b0a445e354
Merge pull request #13203 from mheon/bump_rc5
Bump to v4.0.0-RC5
2022-02-11 16:34:08 -05:00
Chris Evich
a6fbfd47c9
Cirrus: TODO: netavark/aardvark release branches
Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:44 -05:00
Chris Evich
e5644bbf13
Cirrus: Expand netavark testing to include rootless
The list of netavark/aardvark-dns tasks is likely to be
ever-growing for the near-term.  Consolidate them into a single task
entry with a matrix attribute to make future expansions less
YAML-duplicative.  Also, re-arrange it to fall in-between the CNI
integration and system task sections.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:44 -05:00
Chris Evich
1656a23359
Cirrus: Minor - limit release task applicability
This task/test is guaranteed to fail on non-release PRs.  Upon
reviewing actual practice and the release docs, this task should be
limited to PRs with a title containing `release` or `bump` keywords.
Also fix a minor comment typo.

Ref:
https://github.com/containers/podman/pull/13106#pullrequestreview-869855449

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:44 -05:00
Chris Evich
afb39f2e47
Cirrus: Add [CI:BUILD] magic that only builds
This is intended for cases where no code changes were made in this repo.
but something did change which could affect the toolchain.  For example,
`Makefile` or packaging changes.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:44 -05:00
Lokesh Mandvekar
926c3b08ae
CI: fix nightly builds
Nightly builds were failing on CI ever since the Makefile change to have
install target independent of build targets.
See: e4636ebdc8

This commit ensures everything is built before installation.

[NO NEW TESTS NEEDED]

Signed-off-by: Lokesh Mandvekar <lsm5@fedoraproject.org>
2022-02-11 14:49:44 -05:00
Chris Evich
1e3115cf42
Cirrus: Log netavark/aardvark binary build info.
Enabled by:
* https://github.com/containers/netavark/pull/191
* https://github.com/containers/aardvark-dns/pull/36

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:43 -05:00
Chris Evich
66a3be3709
Cirrus: Add netavark/aardvark system test task
Also add a system-test that verifies netavark driver is in use when
magic env. var. is set.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:49:40 -05:00
Chris Evich
6b0d4d9158
Cirrus: Also download aardvark-dns binary
This involves a minor code-change so the download/install can run in a
loop for the two different repositories and binaries.  Given everything
is exactly the same except the URLs and names.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:47:57 -05:00
Chris Evich
b63f61f5cd
Cirrus: Add e2e task w/ upstream netavark
This PR adds the CI mechanisms to obtain the latest upstream netavark
binary, and set a magic env-var to indicate e2e tests should execute
podman with `--network-driver=netavark`.  A future commit implement
this functionality within the e2e tests.

Due to the way the new environment is enabled, the standard task name
is too long for github to display without adding ellipsis.  Force the
custom task name `Netavark Integration` to workaround this.  At some
future point, when netavark is more mainstream/widely supported, this
custom task and upstream binary install can simply be removed - i.e.
netavark will simply be used by default in the normal e2e tasks.

Signed-off-by: Chris Evich <cevich@redhat.com>
2022-02-11 14:44:16 -05:00
Matthew Heon
6a3de93513 Revert minimum API change
CI is barfing and this seems like the most likely cause.

Signed-off-by: Matthew Heon <mheon@redhat.com>
2022-02-11 14:04:02 -05:00
Brent Baude
9688a462e9
netavark e2e tests
enabled e2e tests for netavark

Signed-off-by: Brent Baude <bbaude@redhat.com>
2022-02-11 11:23:24 -05:00
Matthew Heon
92790e98c6 Bump to v4.0.0-dev
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-10 16:15:11 -05:00
Matthew Heon
d7d79ce815 Bump to v4.0.0-RC5
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-10 16:14:01 -05:00
Matthew Heon
5356e36b8e Update release notes for v4.0.0-RC5
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-10 14:20:04 -05:00
Matthew Heon
77ca2498e9 Modify /etc/resolv.conf when connecting/disconnecting
The `podman network connect` and `podman network disconnect`
commands give containers access to different networks than the
ones they were created with; these networks can also have DNS
servers associated with them. Until now, however, we did not
modify resolv.conf as network membership changed.

With this PR, `podman network connect` will add any new
nameservers supported by the new network to the container's
/etc/resolv.conf, and `podman network disconnect` command will do
the opposite, removing the network's nameservers from
`/etc/resolv.conf`.

Fixes #9603

Signed-off-by: Matthew Heon <matthew.heon@pm.me>
2022-02-10 14:05:48 -05:00
Paul Holzinger
f8cd4df1b6 Do not set the network config dir to cni plugin dir
I do not know why this code was added but it is wrong. We should never
use a plugin dir as config dir. Also this will fail for netavark. The
correct default will be set in c/common so podman should not touch it.

[NO NEW TESTS NEEDED]

Ref #13183

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-02-10 14:04:17 -05:00
Paul Holzinger
d0fccbbbba Show API doc for several versions
Right now it is not possible to look at the API version for a specific
version. docs.podman.io always show the latest version from the main
branch. This is not want many users want so they now have the ability to
select a different version.

Fixes #12796

Signed-off-by: Paul Holzinger <pholzing@redhat.com>
2022-02-10 14:03:58 -05:00