maggesandClaude Sonnet 5 51b7262b72
Lint / ShellCheck (push) Successful in 10s
Lint / Validate .plg XML (push) Successful in 10s
Lint / EditorConfig (push) Successful in 4s
Fix five real bugs found by actually installing and running the plugin
First live end-to-end install on real Unraid hardware (all 8 built
packages installed via upgradepkg, rc.podman started, containers
pulled/run/networked/port-mapped) — surfaced five genuine bugs no
amount of container-based CI testing could have caught, since none of
them exist inside the vbatts/slackware:15.0 build container:

1. rc.podman never created $PODMAN_LOG_DIR before redirecting the
   podman system service's output into it, so the service failed to
   even start ("No such file or directory"). Added it alongside the
   existing PODMAN_RUN_DIR mkdir.

2. config/storage.conf hardcoded a [storage] table, and
   podman-config.sh's `sync` step appended a second one at boot with
   the real graphroot/runroot — TOML forbids defining the same table
   twice. Removed the template's [storage] entirely; sync already
   generates the whole thing.

3. config/policy.json had a "_comment" pseudo-field for
   documentation, but containers/image's policy parser rejects any
   unknown top-level key outright. JSON has no comment syntax; moved
   the rationale into docs/ARCHITECTURE.md instead.

4. netavark >= 2.0 dropped its iptables firewall driver entirely
   (verified: passing "iptables" is flatly rejected) — nftables or
   firewalld are the only remaining options, and firewalld needs
   systemd/dbus, which Unraid has neither of. Set firewall_driver =
   "nftables" explicitly and documented that Unraid OS doesn't ship
   the `nft` binary this needs (a slackware64 nftables package works;
   not yet wired into the build/install pipeline — see follow-up).

5. Every container failed with "crun: pivot_root: Invalid argument".
   Root cause: Unraid's / is permanently the kernel's initial "rootfs"
   pseudo-filesystem (Unraid never pivots to a real one at boot — the
   whole OS runs from RAM), and pivot_root(2) unconditionally rejects
   that as the old root. This is not new: Docker/runc hits the exact
   same kernel restriction on this exact host and silently falls back
   to an MS_MOVE-based chroot; crun has no such fallback, only a
   --no-pivot flag with no config-file equivalent. Added
   plugin/sbin/crun-no-pivot.sh, a thin wrapper that scans crun's full
   argument list (podman puts global flags before the subcommand, so
   the subcommand isn't reliably $1) and injects --no-pivot right
   after create/run, and pointed containers.conf's crun runtime at it.
   Also fixed the podman.plg postinstall's chmod glob
   (`podman-*.sh` -> `*.sh`), which would have skipped this new
   non-podman-prefixed sbin script.

Verified end-to-end on the real host: pull, run, real network
connectivity (wget through the container's bridge), and a published
port actually serving HTTP (curl through -p 8099:80 to nginx) all
work. --no-pivot's security tradeoff (disabling one particular
container-escape mitigation) was explicitly discussed with and
approved by the user before committing, given it must be the default
for any container to start at all on this platform.

Follow-up not yet done: nftables (needed for #4) is not yet a
packages/ component in the reproducible build pipeline — it was only
installed manually on the test host for this verification run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-11 23:06:53 +00:00
2026-07-11 12:24:23 +02:00

unraid-podman

A native Unraid plugin that integrates Podman as a first-class container engine, running alongside Docker.

Status: architecture / scaffolding stage. No functional code has been shipped yet. This repository currently defines the target structure and design; see docs/ARCHITECTURE.md for the full technical plan and docs/ROADMAP.md for what's coming.

Goals

  • Run rootful Podman on Unraid with full persistence across reboots (config, images, containers, volumes, networks) despite Unraid's RAM-root design.
  • Coexist cleanly with Docker — no shared storage, network, or firewall conflicts.
  • Follow Unraid's native conventions: .plg installation, Slackware .txz packages, BSD-style rc.d init scripts (no systemd), config on /boot, data on the array/cache.
  • Provide a WebUI in the Dynamix style once the CLI-driven core is stable.
  • Eventually make Docker optional/disable-able once feature parity is reached.

See docs/ARCHITECTURE.md for the full rationale behind every decision below.

Repository structure

.
├── .github/            CI workflows, issue/PR templates, community health files
├── assets/             Icons, screenshots, branding used by the plugin & GUI
├── config/             Default containers/storage/registries config templates
├── docs/               Architecture, install guide, FAQ, troubleshooting, roadmap
├── packages/           Slackware .txz build recipes (podman, conmon, crun, netavark, ...)
├── plugin/             The .plg manifest, rc.d init script, sbin helper scripts,
│                       and the default files deployed to /boot/config/plugins/podman
├── scripts/            Build, release, and developer tooling scripts
└── webui/              Dynamix-style WebUI pages (plugins/podman/), added in a later phase

Installation

Not yet available. Once packages and the .plg manifest are published, installation will be the standard Unraid flow: Plugins → Install Plugin with the .plg URL, or via the Unraid Community Applications store once listed there.

Documentation

  • Architecture — full technical design (directory layout, packaging, init scripts, persistence, networking, autostart, updates, rollback, logging, error handling, future WebUI).
  • Roadmap — phased delivery plan.
  • Install guide — end-user installation steps (draft).
  • Troubleshooting — common problems and diagnostics.
  • FAQ

Contributing

Contributions are welcome — see CONTRIBUTING.md for the dev workflow, coding conventions, and how the packaging pipeline works. Please also review our Code of Conduct.

Security

Rootful Podman's API socket is root-equivalent. See SECURITY.md for the vulnerability disclosure process and known security considerations.

License

Licensed under the MIT License.

S
Description
No description provided
Readme MIT
1 MiB
2026-07-13 23:53:59 +02:00
Languages
JavaScript 29.5%
PHP 28.1%
Shell 25.1%
HTML 9.5%
CSS 7.8%