Files
unraid-podman/webui
maggesandClaude Sonnet 5 5b47b4cc0a Add catatonit/nftables/docker-compose packages, fix CSRF/streaming/storage bugs found by live testing
- Package #9-11: catatonit (pod infra init), nftables (netavark firewall
  backend), docker-compose (external compose provider for `podman compose`)
  — all vendored prebuilt binaries, versions.env pinned, propagated through
  build-packages.sh/release.sh/podman.plg/verify+update-packages.sh.
- Fix WebUI: every POST action was silently failing (empty response body)
  because Unraid's own CSRF protection was never satisfied — app.js now
  sends the page's csrf_token as X-CSRF-Token.
- Fix WebUI: PodmanClient::pullImage() assumed a single JSON response, but
  /images/pull actually streams newline-delimited JSON — every successful
  pull was throwing "Expected a JSON object/array response".
- Fix WebUI: compose.php's up/down status detection had the same
  single-JSON-vs-NDJSON bug for `podman compose ps`, plus stderr was
  corrupting the parse.
- Add cache-busting (?v=<mtime>) to Podman.page's script/style tags so a
  redeployed JS/CSS fix isn't served stale from browser cache.
- Add a reusable modal dialog (app.js openFormModal) replacing
  prompt()/alert() for New Volume/Network/Pull Image.
- Add host-path (bind-mount) support when creating a named volume.
- Add Create Container (image, name, network mode incl. custom networks,
  ports, volumes, env, restart policy, privileged, start-after-create),
  auto-pulling the image on first use since /containers/create doesn't.

All fixes verified live against a real podman system service and, where
reachable, via the actual WebUI over the real socket — not just unit-level.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 11:51:17 +00:00
..

webui/

Dynamix-style WebUI pages, following Unraid's plugin GUI convention of /usr/local/emhttp/plugins/<name>/. webui/plugins/podman/ is staged to that path by the unraid-podman scaffolding package (see packages/unraid-podman/unraid-podman.SlackBuild), which podman.plg installs alongside the other ten packages.

Status: implemented, covering all ten sections from docs/ARCHITECTURE.md, section 18: Dashboard, Containers, Pods, Images, Volumes, Networks, Logs, Terminal, Compose, Settings. Not yet exercised against a real Unraid/Podman install — see docs/ROADMAP.md for what "implemented" does and doesn't cover yet.

webui/mockups/prototype.html is the static, non-PHP clickable mockup this implementation was built against — kept as the visual reference; it is not staged into the package.

Structure

webui/
├── mockups/
│   └── prototype.html         # static approved mockup, not shipped
└── plugins/
    └── podman/
        ├── Podman.page          # page shell: header, sub-nav, one container per panel
        ├── include/
        │   ├── PodmanClient.php # libpod REST API client (talks to podman.sock only)
        │   ├── Config.php       # reads podman.cfg (mirrors podman-common.sh)
        │   ├── bootstrap.php    # shared include + error handling for ajax/*.php
        │   └── helpers.php      # formatting + JSON-response helpers
        ├── ajax/                 # one endpoint per resource, each require()s bootstrap.php
        │   ├── containers.php    # list/start/stop/restart/remove/logs
        │   ├── pods.php
        │   ├── images.php
        │   ├── volumes.php
        │   ├── networks.php
        │   ├── exec.php          # Terminal — see its header comment for API scope
        │   ├── compose.php       # Compose — the one deliberate CLI exception, see header
        │   ├── settings.php      # plugin's own config, not a libpod resource
        │   └── system.php        # Dashboard aggregation
        ├── javascript/
        │   ├── app.js             # shared AJAX helper + sub-tab router
        │   └── <panel>.js         # one module per panel, registers with app.js
        ├── styles/podman.css      # design tokens ported 1:1 from the mockup
        ├── event/                  # official Unraid array-event hooks (see plugin/event/)
        └── images/                  # plugin icon assets

Design constraints (see ARCHITECTURE.md for full rationale)

  • Every panel talks to podman system service over its Unix socket via PodmanClient — no exec()/shell_exec() of the podman binary anywhere in include/ or in the Containers/Pods/Images/Volumes/Networks/ Logs endpoints.
  • Two documented, deliberate exceptions, not oversights:
    • ajax/exec.php (Terminal) uses the real exec REST API, but as one-command-in/output-out rather than a true interactive PTY — libpod's interactive exec needs a persistent hijacked connection that doesn't fit PHP-FPM's request lifecycle. See that file's header comment.
    • ajax/compose.php (Compose) shells out to the podman compose CLI via proc_open() with an argv array (never a shell string) — because no REST endpoint for Compose exists in libpod at all. See that file's header comment.
  • The API socket is root-equivalent; no unauthenticated network exposure beyond what Unraid's own WebUI auth already provides — see .github/SECURITY.md.
  • Dark/light mode via CSS custom properties (prefers-color-scheme + [data-theme] override), matching Unraid's own theme mechanism — no separate theme toggle inside the plugin page.