Add reproducible build system, native Unraid plugin, and WebUI
- versions.env pins podman, conmon, crun, netavark, aardvark-dns, passt, and fuse-overlayfs to verified upstream source checksums; SlackBuild recipes, scripts/build-packages.sh, checksums.sh, release.sh, and update-versions.sh implement the reproducible pipeline; GitHub Actions workflows build in a Slackware container and publish releases without committing any binaries. - plugin/podman.plg installs/updates/removes all eight packages (the seven components plus the plugin's own unraid-podman scaffolding package) via upgradepkg, using the official Unraid array-event hook mechanism (event/disks_mounted, event/stopping) instead of editing /boot/config/go. rc.podman and the sbin/ helper scripts implement storage creation, config seeding/sync, preflight checks, autostart with per-container Safe-Mode, and package verify/update/rollback. - webui/plugins/podman implements the Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, and Settings panels against the approved mockup (webui/mockups/prototype.html), talking to podman system service exclusively via PodmanClient.php (libpod REST API over the Unix socket), with two documented exceptions: Terminal's one-shot exec model and Compose's use of the podman compose CLI, since libpod has no REST equivalent for either. - docs/ARCHITECTURE.md and docs/ROADMAP.md record the design decisions and honest current status (syntax-checked, unit- and integration-tested against fake sockets/servers; not yet run against a real Unraid/Podman/Slackware system). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
# Default containers.conf template for unraid-podman.
|
||||
#
|
||||
# This is a source template shipped in the repository/package. At install/boot
|
||||
# time it is copied to /boot/config/plugins/podman/containers.conf (if not
|
||||
# already present, never overwritten on update) and from there synced to
|
||||
# /etc/containers/containers.conf by rc.podman start.
|
||||
#
|
||||
# See docs/ARCHITECTURE.md section 6.1 (Start-/Stop-Skripte) and section 7
|
||||
# (Persistenz-Strategie). Placeholder — real defaults to be tuned during MVP
|
||||
# implementation.
|
||||
#
|
||||
# Full reference: https://github.com/containers/common/blob/main/docs/containers.conf.5.md
|
||||
|
||||
[containers]
|
||||
# TODO: default ulimits, log driver (k8s-file, see docs/ARCHITECTURE.md section 15), etc.
|
||||
|
||||
[engine]
|
||||
# TODO: static_dir / volume_path / runroot overrides pointing at the cache-pool
|
||||
# backed storage location instead of RAM-root defaults.
|
||||
|
||||
[network]
|
||||
# TODO: default network backend (netavark), default subnet range distinct from
|
||||
# Docker's docker0 range — see docs/ARCHITECTURE.md section 8.
|
||||
@@ -0,0 +1,25 @@
|
||||
# Example plugin settings file for unraid-podman.
|
||||
#
|
||||
# The real, user-editable copy of this file lives on the flash device at
|
||||
# /boot/config/plugins/podman/podman.cfg and is the source of truth read by
|
||||
# rc.podman at every start. See docs/ARCHITECTURE.md section 4.1 and 7.
|
||||
#
|
||||
# Format: simple KEY="value" pairs (bash-sourceable), matching the convention
|
||||
# used by Unraid's own /boot/config/docker.cfg.
|
||||
|
||||
# Path to the directory holding podman.img (cache pool or array disk).
|
||||
# TODO: finalize default; must NOT be a path under /mnt/user.
|
||||
STORAGE_PATH="/mnt/cache/system/podman"
|
||||
|
||||
# Size of the podman.img loopback image, in GiB, used only on first creation.
|
||||
STORAGE_IMAGE_SIZE_GB="20"
|
||||
|
||||
# Whether rc.podman should start automatically when the array starts.
|
||||
PODMAN_ENABLED="yes"
|
||||
|
||||
# Per-container stop timeout, in seconds, used by `rc.podman stop`.
|
||||
STOP_TIMEOUT="10"
|
||||
|
||||
# Config schema version, used by the migration logic described in
|
||||
# docs/ARCHITECTURE.md section 13.1.
|
||||
CONFIG_SCHEMA_VERSION="1"
|
||||
@@ -0,0 +1,11 @@
|
||||
{
|
||||
"_comment": "Default container image signature verification policy. Placeholder: accepts all images without signature verification, matching Docker's default trust model on Unraid today. See docs/ARCHITECTURE.md section 10 (Images). Revisit before a 1.0 release if signed-image verification becomes a goal.",
|
||||
"default": [
|
||||
{ "type": "insecureAcceptAnything" }
|
||||
],
|
||||
"transports": {
|
||||
"docker-daemon": {
|
||||
"": [{ "type": "insecureAcceptAnything" }]
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,17 @@
|
||||
# Default registries.conf template for unraid-podman.
|
||||
#
|
||||
# Pre-configures unqualified-search registries explicitly, since there is no
|
||||
# interactive TTY to prompt the user in a boot-script context.
|
||||
# See docs/ARCHITECTURE.md section 10 (Images).
|
||||
#
|
||||
# Full reference: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md
|
||||
|
||||
unqualified-search-registries = ["docker.io"]
|
||||
|
||||
# TODO: consider pre-listing common registries (ghcr.io, quay.io, lscr.io) as
|
||||
# short-name aliases, matching what Unraid Community Applications users expect
|
||||
# from Docker Hub-centric templates today.
|
||||
|
||||
[[registry]]
|
||||
prefix = "docker.io"
|
||||
location = "docker.io"
|
||||
@@ -0,0 +1,21 @@
|
||||
# Default storage.conf template for unraid-podman.
|
||||
#
|
||||
# Defines the Podman storage graph root/driver. On Unraid this MUST point at
|
||||
# the mounted podman.img loopback (or equivalent cache-pool/disk path), never
|
||||
# at a path under /mnt/user (FUSE) or RAM-root /var/lib/containers directly.
|
||||
# See docs/ARCHITECTURE.md section 4.3 and section 10 (Images).
|
||||
#
|
||||
# Full reference: https://github.com/containers/storage/blob/main/docs/containers-storage.conf.5.md
|
||||
|
||||
[storage]
|
||||
driver = "overlay"
|
||||
# runroot and graphroot are set at runtime by rc.podman based on
|
||||
# /boot/config/plugins/podman/podman.cfg (configurable storage location),
|
||||
# not hardcoded here. TODO: document the exact substitution mechanism once
|
||||
# rc.podman is implemented.
|
||||
# graphroot = "/var/lib/containers/storage"
|
||||
# runroot = "/var/run/containers/storage"
|
||||
|
||||
[storage.options]
|
||||
# TODO: overlay-specific mount options once the loopback filesystem
|
||||
# (XFS with ftype=1, or BTRFS) is finalized.
|
||||
Reference in New Issue
Block a user