# Default containers.conf template for unraid-podman. # # This is a source template shipped in the repository/package. At install/boot # time it is copied to /boot/config/plugins/podman/containers.conf (if not # already present, never overwritten on update) and from there synced to # /etc/containers/containers.conf by rc.podman start. # # See docs/ARCHITECTURE.md section 6.1 (Start-/Stop-Skripte) and section 7 # (Persistenz-Strategie). Placeholder — real defaults to be tuned during MVP # implementation. # # Full reference: https://github.com/containers/common/blob/main/docs/containers.conf.5.md [containers] # TODO: default ulimits, log driver (k8s-file, see docs/ARCHITECTURE.md section 15), etc. [engine] # TODO: static_dir / volume_path / runroot overrides pointing at the cache-pool # backed storage location instead of RAM-root defaults. [engine.runtimes] # Unraid's / is the kernel's initial 'rootfs' pseudo-filesystem — Unraid # never pivots to a real one during boot, the whole OS runs from RAM — and # pivot_root(2) unconditionally rejects that as the "old root" (EINVAL). # runc (what Docker uses) silently falls back to an MS_MOVE-based chroot # in that situation; crun has no such fallback, only a --no-pivot flag on # `create`/`run` with no config-file equivalent — so podman is pointed at # a thin wrapper (installed by the unraid-podman package, see # plugin/sbin/crun-no-pivot.sh) that injects it, instead of crun directly. # Verified live: without this, every container fails with # "crun: pivot_root: Invalid argument: OCI runtime error". crun = ["/usr/local/sbin/crun-no-pivot.sh"] [network] # TODO: default subnet range distinct from Docker's docker0 range — see # docs/ARCHITECTURE.md section 8. # # netavark >= 2.0 dropped its iptables firewall driver entirely — only # nftables and firewalld remain (verified against the actual netavark # binary; "iptables" is rejected with "Must provide a valid firewall # backend"). firewalld needs systemd/dbus, which Unraid has neither of, so # nftables (netavark's own default — explicit here so that stays true even # if netavark's default ever changes) is the only viable driver. Unraid OS # does not ship the `nft` binary this needs — see docs/ARCHITECTURE.md # section 8 for how it's provisioned. network_backend = "netavark" firewall_driver = "nftables"