Re: F27 System Wide Change: Graphical Applications as Flatpaks

2017-07-17 Thread Daniel Walsh
On 07/17/2017 03:14 PM, Neal Gompa wrote: On Mon, Jul 17, 2017 at 2:48 PM, Michael Stahl wrote: On 17.07.2017 19:26, Richard W.M. Jones wrote: On Mon, Jul 17, 2017 at 12:03:13PM +0200, Michael Stahl wrote: On 16.07.2017 12:54, Richard W.M. Jones wrote: On Fri, Jul 14,

Wrote a new blog for OpenSource.Com on evolution of containers.

2017-07-10 Thread Daniel Walsh
https://opensource.com/article/17/7/how-linux-containers-evolved If you like it, please social Media this message out. ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Re: Fedora packager environment in a docker container

2017-04-24 Thread Daniel Walsh
On 04/24/2017 08:08 AM, Patrick Uiterwijk wrote: Hi, On Mon, Apr 24, 2017 at 12:29 PM, Michal Minar wrote: Did anyone successfully set up his fedora packaging environment in a docker container? I didn't get past `kinit mimi...@fedoraproject.org` in a container. It

Re: Fedora packager environment in a docker container

2017-04-24 Thread Daniel Walsh
On 04/24/2017 06:29 AM, Michal Minar wrote: Did anyone successfully set up his fedora packaging environment in a docker container? I didn't get past `kinit mimi...@fedoraproject.org ` in a container. It gives me: Invalid UID in persistent keyring name while

Re: Many 'map' SELinux denials in current Rawhide

2017-08-18 Thread Daniel Walsh
On 08/15/2017 02:50 PM, Joonas Sarajärvi wrote: Adam Williamson kirjoitti 15.08.2017 klo 02:37: Of course, for day-to-day Rawhide users, booting with 'enforcing=0' can work around these issues for now (or you could, I suppose, create a local policy that just blanket allowed the 'map' permission

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Daniel Walsh
On 06/20/2017 04:21 AM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 09:25:49AM +0200, Pavel Cahyna wrote: Hi, On Tue, Jun 20, 2017 at 07:42:27AM +0200, Jan Kurik wrote: = System Wide Change: Kerberos KCM credential cache by default = https://fedoraproject.org/wiki/Changes/KerberosKCMCache

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-21 Thread Daniel Walsh
On 06/21/2017 02:23 AM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 04:23:30PM -0400, Daniel Walsh wrote: On 06/20/2017 02:45 PM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 08:55:49AM -0400, Daniel Walsh wrote: On 06/20/2017 04:21 AM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 09:25:49AM

Re: F27 System Wide Change: Kerberos KCM credential cache by default

2017-06-20 Thread Daniel Walsh
On 06/20/2017 02:45 PM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 08:55:49AM -0400, Daniel Walsh wrote: On 06/20/2017 04:21 AM, Jakub Hrozek wrote: On Tue, Jun 20, 2017 at 09:25:49AM +0200, Pavel Cahyna wrote: Hi, On Tue, Jun 20, 2017 at 07:42:27AM +0200, Jan Kurik wrote: = System Wide

Re: Converting selinux commands into a policy file

2017-09-14 Thread Daniel Walsh
On 09/14/2017 10:25 AM, Richard Shaw wrote: I have been working on packaging the Ubiquity Unifi controller software for Fedora and EPEL and the package actually works pretty well. I've created a review request on RPM Fusion non-free since it's not FOSS and I've only been given permission to

Re: GnuPG 2.2.0 and replacement of GnuPG1

2017-09-19 Thread Daniel Walsh
On 09/17/2017 02:12 PM, Brian Exelbierd wrote: On Thu, Sep 7, 2017, at 02:25 PM, Dominik 'Rathann' Mierzejewski wrote: On Sunday, 03 September 2017 at 13:45, Igor Gnatenko wrote: GnuPG 2.2.0 has --enable-gpg-is-gpg2 which would install compat symlink from /usr/bin/gpg to /usr/bin/gpg2.. Is

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-06 Thread Daniel Walsh
On 10/06/2017 10:14 AM, Mark Wielaard wrote: On Mon, 2017-09-18 at 16:48 +0200, Tomas Tomecek wrote: we managed to move tools container from Fedora Dockerfiles github repo to Fedora infra [1]. As a side effects, we put systemtap in a dedicated container. We would very much appreciate your

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
On 10/05/2017 01:00 PM, Frank Ch. Eigler wrote: wcohen forwarded: [...] [root@dhcp23-91 ~]# atomic run --spc candidate-registry.fedoraproject.org/f26/systemtap docker run --cap-add SYS_MODULE -v

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
On 10/05/2017 01:18 PM, Jeremy Eder wrote: setenforce 0 works...security-opt label:disable does not. On Thu, Oct 5, 2017 at 1:06 PM, Daniel Walsh <dwa...@redhat.com <mailto:dwa...@redhat.com>> wrote: On 10/05/2017 01:00 PM, Frank Ch. Eigler wrote: wcoh

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
On 10/05/2017 01:11 PM, Frank Ch. Eigler wrote: Hi, Dan - [...] Rather then putting the system into permissive mode, you should run a privileged container "atomic run --spc " fails similarly on f26, despite its underlying "docker run --cap-add SYS_MODULE ..." parts. or at least disable

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
On 10/05/2017 01:55 PM, Frank Ch. Eigler wrote: Hi, Dan - On Thu, Oct 05, 2017 at 01:49:48PM -0400, Daniel Walsh wrote: [...] But really for something like this, it would be better to just run it --privileged. There is [no] security confinement present in what you are doing. Yup. I thought

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
:25 PM, Daniel Walsh <dwa...@redhat.com <mailto:dwa...@redhat.com>> wrote: On 10/05/2017 01:18 PM, Jeremy Eder wrote: setenforce 0 works...security-opt label:disable does not. On Thu, Oct 5, 2017 at 1:06 PM, Daniel Walsh <dwa...@redhat.com <mailto:d

Re: [atomic-devel] tools and systemtap containers are available in Fedora

2017-10-05 Thread Daniel Walsh
On 10/05/2017 01:47 PM, Frank Ch. Eigler wrote: Hi, Dan - Could you show the docker line that atomic run is executing? % atomic run --spc candidate-registry.fedoraproject.org/f26/systemtap /usr/share/systemtap/examples/io/iotop.stp docker run --cap-add SYS_MODULE -v

Re: systemd in non-privileged container

2018-04-27 Thread Daniel Walsh
On 04/27/2018 11:41 AM, Lennart Poettering wrote: On Fr, 27.04.18 17:27, Pavel Raiskup (prais...@redhat.com) wrote: Hi all, just wanted to let you know about trivial experiment [1] with systemd in container. Non-privileged systemd can now pretty fine run in docker container (tested on Fedora

I would like to propose that we turn on XFS Reflink in Fedora 29 by default

2018-04-28 Thread Daniel Walsh
We are adding some features to container projects for User Namespace support that can take advantage of XFS Reflink.  I have talked to some of the XFS Reflink kernel engineers in Red Hat and they have informed me that they believe it is ready to be turned on by default. I am not sure who in

Re: systemd in non-privileged container

2018-04-30 Thread Daniel Walsh
On 04/30/2018 10:42 AM, James Hogarth wrote: On 27 April 2018 at 17:47, Pavel Raiskup wrote: On Friday, April 27, 2018 5:41:19 PM CEST Lennart Poettering wrote: On Fr, 27.04.18 17:27, Pavel Raiskup (prais...@redhat.com) wrote: Hi all, just wanted to let you know about

Re: F28 System Wide Change: Rename "nobody" user

2018-01-15 Thread Daniel Walsh
On 01/13/2018 10:18 AM, Steve Dickson wrote: On 01/13/2018 08:50 AM, Steve Dickson wrote: So I guess the next question is what the current nobody id (25) used for and why does it exist? Doing some research on this back in Aug 2001 nfsnobody was added to nfs-utils for the reasons stated in

Re: F28 System Wide Change: Rename "nobody" user

2018-01-12 Thread Daniel Walsh
On 01/12/2018 10:41 AM, Steve Dickson wrote: On 01/12/2018 09:47 AM, Lennart Poettering wrote: On Fr, 12.01.18 09:28, Steve Dickson (ste...@redhat.com) wrote: User namespacing is a Linux kernel feature. It's most well known consumers are probably Docker, and maybe flatpak/bubblewrap and LXC.

Re: F28 Self Contained Change: Atomic, Cloud and Docker images for s390x

2018-01-30 Thread Daniel Walsh
On 01/30/2018 11:50 AM, Jan Kurik wrote: = Proposed Self Contained Change: Atomic, Cloud and Docker images for s390x = https://fedoraproject.org/wiki/Changes/Atomic_Cloud_and_Docker_images_for_s390x Change owner(s): * Sinny Kumari This change is to bring s390x architecture closer to other

Re: F28 Self Contained Change: Atomic, Cloud and Docker images for s390x

2018-02-02 Thread Daniel Walsh
On 01/31/2018 06:26 PM, Josh Boyer wrote: On Tue, Jan 30, 2018 at 12:42 PM, Daniel Walsh <dwa...@redhat.com> wrote: On 01/30/2018 11:50 AM, Jan Kurik wrote: = Proposed Self Contained Change: Atomic, Cloud and Docker images for s390x = https://fedoraproject.org/wiki/C

Re: F28 Self Contained Change: Atomic, Cloud and Docker images for s390x

2018-02-10 Thread Daniel Walsh
On 02/09/2018 03:13 AM, Zbigniew Jędrzejewski-Szmek wrote: On Mon, Feb 05, 2018 at 12:20:09PM +0530, Sinny Kumari wrote: On Fri, Feb 2, 2018 at 8:25 PM, Daniel Walsh <dwa...@redhat.com> wrote: Not yet. We are working on packaging podman which would give users the same experience as Dock

Re: Starting a Container SIG

2018-07-25 Thread Daniel Walsh
On 07/25/2018 01:09 PM, Clement Verna wrote: Greeting all, The container effort in Fedora has until now been looked after by the Atomic WG, since this Working Group is now going to focus mostly on Fedora CoreOS, I propose to create a new container SIG to regroup people interested in the

pam_cgfs.so support for Fedora?

2018-09-09 Thread Daniel Walsh
Has anyone looked at supporting pam_cgfs.so in Fedora. This question was asked here. https://github.com/containers/libpod/issues/1429 ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to

Re: In the OpenShift Origin/CRI-O/Kubernetes effort we have a dilemma.

2018-06-29 Thread Daniel Walsh
On 06/29/2018 10:03 AM, Nicolas Mailhot wrote: Le 2018-06-29 14:31, Daniel Walsh a écrit : Hi, Users of OpenSHift Origin require CRI-O 1.10 right now.  But Kubernetes users want to try out the latest packages for kubernetes 1.11 which would require CRI-O 1.11.  Origin might not be ready

In the OpenShift Origin/CRI-O/Kubernetes effort we have a dilemma.

2018-06-29 Thread Daniel Walsh
Users of OpenSHift Origin require CRI-O 1.10 right now.  But Kubernetes users want to try out the latest packages for kubernetes 1.11 which would require CRI-O 1.11.  Origin might not be ready to move to Kubernetes 1.11 for a while. Bottom line we want to be able to ship CRI-0 1.10.* and

I will be giving a Fedora Classroom on Tuesday at 11:00 EST on Buildah

2019-01-14 Thread Daniel Walsh
Building Container Images with Buildah. https://fedoramagazine.org/fedora-classroom-building-container-images-with-buildah/ ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org

FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-14 Thread Daniel Walsh
I have opened a Change Request to change the defaults for Fedora 31 to Cgroups V2.  I am looking for what packages will be affected by this change.   Basically any package that adjusts Cgroups via the CgroupFS, my understanding is working the the systemd APIs, you should be fine. Packages That I

Re: FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-14 Thread Daniel Walsh
Ok I guess this will not effect anaconda, just affect systemd. On 2/14/19 1:58 PM, Daniel Walsh wrote: > On 2/14/19 9:55 AM, jkone...@redhat.com wrote: >> Hi Dan, >> >> How the Anaconda will be affected? I'm not aware of any cgroups control >> from Anaconda side or

Re: FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-14 Thread Daniel Walsh
On 2/14/19 10:49 AM, Daniel P. Berrangé wrote: > On Thu, Feb 14, 2019 at 08:10:09AM -0500, Daniel Walsh wrote: >> I have opened a Change Request to change the defaults for Fedora 31 to >> Cgroups V2.  I am looking for what packages will be affected by this >> change.  

Re: FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-14 Thread Daniel Walsh
a It will need to change the default kernel option to enable it. > On Thu, 2019-02-14 at 08:10 -0500, Daniel Walsh wrote: >> I have opened a Change Request to change the defaults for Fedora 31 >> to >> Cgroups V2. I am looking for what packages will be affected by this >> chang

Re: FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-15 Thread Daniel Walsh
rote: >>> >>> On Thu, Feb 14, 2019 at 08:10:09AM -0500, Daniel Walsh wrote: >>>> I have opened a Change Request to change the defaults for Fedora 31 to >>>> Cgroups V2.  I am looking for what packages will be affected by this >>>> c

Re: FYI https://fedoraproject.org/wiki/Changes/CGroupsV2

2019-02-15 Thread Daniel Walsh
On 2/15/19 7:02 AM, Lennart Poettering wrote: > On Fr, 15.02.19 12:55, Zygmunt Krynicki (m...@zygoon.pl) wrote: > >> I’m happy to work on this issue once it becomes „pressing” and once >> the prerequisites are available. If F30 disables v1 entirely and has >> a kernel where we can get device,

Re: Self Introduction: Jordan Ogas

2019-05-16 Thread Daniel Walsh
On 5/16/19 3:17 PM, Ogas, Jordan Andrew via devel wrote: > > Greetings, > >   > > My name is Jordan, I'm a member of the Programming and Runtime Environment > > team for the High Performance Computing Division (HPC) at the Los Alamos > > National Laboratory (LANL). I have been encouraged by my

Re: Self Introduction: Jordan Ogas

2019-05-17 Thread Daniel Walsh
On 5/17/19 11:15 AM, Ogas, Jordan Andrew wrote: > > Not personally but my team are experimenting with Buildah/Podman. > I am really interested in rootless podman as an alternative to Singularity, And if there are any shortcomings. > >   > > *From: *Daniel Walsh > *Organiz

Re: Self Introduction: Jordan Ogas

2019-05-17 Thread Daniel Walsh
On 5/17/19 2:34 PM, Jonathan Billings wrote: > On Fri, May 17, 2019 at 01:56:20PM -0400, Daniel Walsh wrote: >> On 5/17/19 11:15 AM, Ogas, Jordan Andrew wrote: >>> Not personally but my team are experimenting with Buildah/Podman. >>> >> I am really interested in

Re: Self Introduction: Jordan Ogas

2019-05-17 Thread Daniel Walsh
uidmap and newgidmap use FileCaps and thus only have SETUID and SETGID respectively.  getcap /usr/bin/new*idmap /usr/bin/newgidmap = cap_setgid+ep /usr/bin/newuidmap = cap_setuid+ep >   > > Best, > > Jordan > >   > > *From: *Daniel Walsh > *Organization: *Red Hat &

Re: New mailing lists available for podman/libpod

2019-06-14 Thread Daniel Walsh
On 6/13/19 3:14 PM, Neal Gompa wrote: > On Thu, Jun 13, 2019 at 3:13 PM Daniel Walsh wrote: >> Send an email to: podman-j...@lists.podman.io with the word "subscribe" >> in the title, or by going to https://lists.podman.io and scrolling to >> the bottom of that pa

Re: New mailing lists available for podman/libpod

2019-06-14 Thread Daniel Walsh
On 6/13/19 3:14 PM, Neal Gompa wrote: > On Thu, Jun 13, 2019 at 3:13 PM Daniel Walsh wrote: >> Send an email to: podman-j...@lists.podman.io with the word "subscribe" >> in the title, or by going to https://lists.podman.io and scrolling to >> the bottom of that pa

New mailing lists available for podman/libpod

2019-06-13 Thread Daniel Walsh
Send an email to: podman-j...@lists.podman.io with the word "subscribe" in the title, or by going to https://lists.podman.io and scrolling to the bottom of that page to subscribe. ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe

Re: Where are armv7hl, i686 and ppc64le Container tar.xz files?

2019-05-20 Thread Daniel Walsh
On 5/19/19 9:11 AM, Jun Aruga wrote: > I am suggesting a new feature "podman buildx" like "docker buildx" > that makes a better multi arch build experience. > See below URL if you are interested in it. > > Supporting building multi-platform images (podman buildx) >

Re: module load inside rpmbuild inside docker

2019-05-04 Thread Daniel Walsh
On 5/3/19 6:00 PM, Christoph Junghans wrote: > Hi, > > I wanted to bump the legion package to 19.04.0 > (https://bugzilla.redhat.com/show_bug.cgi?id=1705033), however for > some reason all tests segfault with openmpi > (https://koji.fedoraproject.org/koji/taskinfo?taskID=34577005), so I > reported

Re: Orphaning moby-engine (Docker)

2019-07-11 Thread Daniel Walsh
On 7/11/19 4:32 PM, Olivier Lemasle wrote: > On Wednesday, 3 July 2019 19:56:47 CEST David Michael wrote: >> I have orphaned moby-engine, the community Docker package in Fedora, >> due to no longer working in a role where I can maintain it as part of >> the job. If anyone wants to take it, it is

Re: Orphaning moby-engine (Docker)

2019-07-13 Thread Daniel Walsh
On 7/11/19 7:57 PM, David Michael wrote: > On Thu, Jul 11, 2019 at 5:22 PM Olivier Lemasle wrote: >> On Wednesday, 3 July 2019 19:56:47 CEST David Michael wrote: >>> I have orphaned moby-engine, the community Docker package in Fedora, >>> due to no longer working in a role where I can maintain it

Re: Fedora 31 System-Wide Change proposal: Modify Fedora 31 to use CgroupsV2 by default

2019-07-08 Thread Daniel Walsh
On 7/4/19 5:21 AM, Zbigniew Jędrzejewski-Szmek wrote: > On Wed, Jul 03, 2019 at 04:23:24PM -0400, Ben Cotton wrote: >> https://fedoraproject.org/wiki/Changes/CGroupsV2 >> >> == Summary == >> The kernel has had some support for CgroupsV2 for some time, and yet >> no one has used it because it is

Re: Fedora 31 System-Wide Change proposal: Modify Fedora 31 to use CgroupsV2 by default

2019-07-08 Thread Daniel Walsh
On 7/8/19 11:00 AM, Neal Gompa wrote: > On Mon, Jul 8, 2019 at 10:39 AM Daniel Walsh wrote: >> Their has not been much progress on runc development for this, which >> might be a blocker. >> >> In the Podman/Buildah world, we have support for crun, an alternate OCI >

Re: Orphaning moby-engine (Docker)

2019-07-08 Thread Daniel Walsh
On 7/3/19 6:50 PM, Stephen John Smoogen wrote: > > > On Wed, 3 Jul 2019 at 17:15, Robert-André Mauchin > wrote: > > On Wednesday, 3 July 2019 19:56:47 CEST David Michael wrote: > > I have orphaned moby-engine, the community Docker package in Fedora, > > due

Re: Join the new Minimization Team

2019-08-21 Thread Daniel Walsh
On 8/21/19 5:00 AM, Tomasz Torcz wrote: > On Tue, Aug 20, 2019 at 10:52:18PM -0700, John Harris wrote: >> Having a container without a package manager sounds like the worst possible >> thing to add to an already poorly implemented solution. In reality, >> containers, regardless of what they're

Re: systemd-sysusers versus containers

2019-09-17 Thread Daniel Walsh
On 9/17/19 8:04 AM, Colin Walters wrote: > > On Mon, Sep 16, 2019, at 12:45 PM, Troy Dawson wrote: >> systemd-sysusers seeks to unify user creation[1]. It also has the >> benefit of being able to create users on bootup. But, it pulls in the >> entire systemd infrastructure with all it's

Re: Join the new Minimization Team

2019-07-30 Thread Daniel Walsh
If you want small images, just use buildah. ctr=$(buildah from scratch) mnt=$(buildah mount $ctr) COPY/DnF/make install into $mnt buildah config ... $ctr buildah commit $ctr NEWIMAGE buildah push NEWIMAGE CONTAINERREGGISTY... If you want to build off of base images, you can probably create them

Re: Where are armv7hl, i686 and ppc64le Container tar.xz files?

2019-08-06 Thread Daniel Walsh
On 8/6/19 9:15 AM, Jun Aruga wrote: >>> Please come! >>> >> Would love to see your examples use podman... > Sorry here is the podman's example. > And no worry. podman's examples are used as much as possible in my talk! > > ``` > $ uname -m > x86_64 > > $ podman run --rm -t arm64v8/fedora:30 uname

Re: Where are armv7hl, i686 and ppc64le Container tar.xz files?

2019-08-06 Thread Daniel Walsh
On 8/6/19 7:56 AM, Jun Aruga wrote: >> ``` >> $ docker run --rm -t arm64v8/fedora:30 uname -m > standard_init_linux.go:207: exec user process caused "no such file or > directory" >> $ docker run --rm --privileged multiarch/qemu-user-static:register --reset >> $ docker run --rm -t

Re: Join the new Minimization Team

2019-08-08 Thread Daniel Walsh
On 8/7/19 11:24 AM, Colin Walters wrote: > > On Tue, Jul 30, 2019, at 3:52 PM, Daniel Walsh wrote: >> If you want small images, just use buildah. > Dockerfile-based multi-stage builds are significantly more popular than this > and should really be mentioned first. Buildah su

Re: kata containers: adding a docker runtime

2019-09-27 Thread Daniel Walsh
On 9/25/19 8:26 PM, Tomasz Torcz wrote: > On Wed, Sep 25, 2019 at 12:14:54PM +0200, Christophe de Dinechin wrote: >> Hi Lokesh, >> >> >> As you know, I have been working on bringing kata containers to Fedora. >> >> Since this adds a new runtime, the docker.service file would need to be >> modified

Re: Trouble with install ordering and SELinux config

2019-11-01 Thread Daniel Walsh
Flat pack should be doing a requires(post): selinux-policy-base To make sure it is installed before flatpack. On 11/1/19 2:51 PM, Tim Zabel wrote: > On Fri, 2019-11-01 at 12:02 -0600, Orion Poplawski wrote: >> My F31 kickstart install is failing with: >> >> DNF error: Error in POSTIN scriptlet in

Re: Fedora 32 System-Wide Change proposal: Build Python 3 to statically link with libpython3.8.a for better performance

2019-11-08 Thread Daniel Walsh
On 11/8/19 5:16 PM, John M. Harris Jr wrote: > On Tuesday, November 5, 2019 12:09:55 PM MST Martin Kolman wrote: >> On Tue, 2019-11-05 at 19:41 +0100, Kevin Kofler wrote: >> Python 3 traditionally in Fedora was built with a shared library libpython3.?.so and the final binary was

I wrote a blog on why we moved Fedora 31 to cgroup V2

2019-11-11 Thread Daniel Walsh
https://www.redhat.com/sysadmin/fedora-31-control-group-v2 If you like it, please put it out on social media. ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of

https://bodhi.fedoraproject.org/updates/new

2019-12-12 Thread Daniel Walsh
Is not working for me. I am trying to release container-selinux-2.124.0 to F31 but the web app just spins after I hit submit.  No error messages but no success.  Am I doing something wrong or is the updates system broken? ___ devel mailing list --

Re: Should we discontinue the Python Classroom Lab?

2019-12-05 Thread Daniel Walsh
On 12/5/19 9:55 AM, John M. Harris Jr wrote: > On Thursday, December 5, 2019 3:44:50 AM MST Miro Hrončok wrote: >> - Docker is broken >> - one of the main ideas was to produce a Docker image >> - the Docker instructions on the download page [4] are not working >> - not even when

Re: Should we discontinue the Python Classroom Lab?

2019-12-06 Thread Daniel Walsh
On 12/6/19 5:39 AM, Nicolas Mailhot via devel wrote: > Le jeudi 05 décembre 2019 à 16:42 -0700, John M. Harris Jr a écrit : >> Why in the world was Docker removed? Docker is the most popular >> container >> technology, so if we must embrace the "container" systems, why not >> include the most

Great article by Valentin Rothberg on Running Podman in systemd unit files.

2019-12-16 Thread Daniel Walsh
This is one of our most common questions, and why we are adding podman generate systemd ... People are interested in running containers as standard services on linux systems.  Valentin dug deep into how to do this. He explains it all here. 

How do you Remove packages from the distro?

2019-10-23 Thread Daniel Walsh
 How do I go about removing packages from Fedora Distro.  I want to drop oci-systemd-hook and oci-register-machine?  I would love to remove them from f31 but it might be too late. ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe

Re: How do you Remove packages from the distro?

2019-10-23 Thread Daniel Walsh
On 10/23/19 10:05 AM, Stephen Gallagher wrote: > On Wed, Oct 23, 2019 at 9:40 AM Daniel Walsh wrote: >> How do I go about removing packages from Fedora Distro. I want to drop >> oci-systemd-hook and oci-register-machine? I would love to remove them >> from f31 but it m

Re: Fedora & Containers

2020-02-26 Thread Daniel Walsh
On 2/25/20 12:05 PM, Michal Schorm wrote: > Hello, > > Will anybody be able to explain to me the current state of the > containers & containerization in Fedora, please? > > I have some questions, but the more I searched for whom & where to > ask, the more confused I became. > > -- > > 1) There ́s

Re: mock inside docker

2020-03-05 Thread Daniel Walsh
Would like to know if this works with Podman. On 3/5/20 11:22, Frantisek Zatloukal wrote: > Hi, > > adding "--no-bootstrap-chroot" wouldn't help? > > On Thu, Mar 5, 2020 at 3:11 PM Christoph Junghans > wrote: > > Hi, > > if I am trying to run mock inside

Re: mock inside docker

2020-03-05 Thread Daniel Walsh
On 3/5/20 11:40, Miro Hrončok wrote: > On 05. 03. 20 15:09, Christoph Junghans wrote: >> Hi, >> >> if I am trying to run mock inside docker, I am getting the following >> error: >> INFO: Results and/or logs in: /var/lib/mock/fedora-rawhide-x86_64/result >> ERROR: Command failed: >>   # /bin/mount

Re: Shebang spawning podman/docker containerized interpreter?

2020-04-15 Thread Daniel Walsh
On 4/15/20 15:01, clime wrote: > On Wed, 15 Apr 2020 at 09:50, Pavel Raiskup wrote: >> Hey all, I'd like to write scripts like: >> >> $ cat script >> #! /bin/shebang which python3-evaluates this in container from image FOO >> print("Hello world") >> >> .. and be able to run them just

Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-04-16 Thread Daniel Walsh
On 4/15/20 17:06, James Cassell wrote: > On Wed, Apr 15, 2020, at 1:27 PM, Daniel Walsh wrote: >> On 4/15/20 10:07, Lennart Poettering wrote: >>> On Di, 14.04.20 15:57, James Cassell (fedoraproj...@cyberpear.com) wrote: >>> >>>> On Tue, Apr 14, 2020, at

Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-04-15 Thread Daniel Walsh
On 4/14/20 17:26, Michael Catanzaro wrote: > On Tue, Apr 14, 2020 at 8:48 pm, Zbigniew Jędrzejewski-Szmek > wrote: >> I guess the lesson here is the nsswitch.conf change should be >> clarified in the proposal. > > OK, I've just added it at the end of this part here: > > "systemd-libs currently

Re: Fedora 33 System-Wide Change proposal: systemd-resolved

2020-04-15 Thread Daniel Walsh
On 4/15/20 10:07, Lennart Poettering wrote: > On Di, 14.04.20 15:57, James Cassell (fedoraproj...@cyberpear.com) wrote: > >> On Tue, Apr 14, 2020, at 3:23 PM, Ben Cotton wrote: >>> https://fedoraproject.org/wiki/Changes/systemd-resolved >>> >>> == Summary == >>> >>> Enable systemd-resolved by

New blog on speeding up container image builds using Buildah and dnf.

2020-03-17 Thread Daniel Walsh
https://www.redhat.com/sysadmin/speeding-container-buildah ___ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct:

Re: F33 podman: unpacking of archive failed cpio: cap_set_file

2020-10-05 Thread Daniel Walsh
On 10/5/20 02:13, Lumír Balhar wrote: On 10/2/20 9:52 PM, Daniel Walsh wrote: On 10/2/20 06:09, Lumír Balhar wrote: Hello. I have fully upgraded Fedora 33 on my laptop and when I try to use podman and install httpd package into container, I get the following error message: Error unpacking

Re: Suspicious downgrades when upgrading from F32 to F33: containers-common, fuse-overlayfs, strace, thunderbird

2020-08-25 Thread Daniel Walsh
On 8/24/20 07:00, Miro Hrončok wrote: > Hello. > > The following packages are downgrades when I attempt upgrade from > Fedora 32 to Fedora 33: > > - containers-common (skopeo) 1:1.1.1 -> 1:1.0.1 > - fuse-overlayfs 1.1.2 -> 1.1.0 > - strace 5.8 -> 5.7.0.6.7ab6 > - thunderbird 668.11.0 -> 8.10.0 > >

Re: F33 podman: unpacking of archive failed cpio: cap_set_file

2020-10-02 Thread Daniel Walsh
On 10/2/20 06:09, Lumír Balhar wrote: Hello. I have fully upgraded Fedora 33 on my laptop and when I try to use podman and install httpd package into container, I get the following error message: Error unpacking rpm package httpd-2.4.46-1.fc32.x86_64 error: unpacking of archive failed on

Re: Package Review SELinux help

2020-06-29 Thread Daniel Walsh
On 6/26/20 14:39, Robert-André Mauchin wrote: > Hello, > > > I know next to nothing about SELinux so I'd like some help about the Bitcoin > Package Review by negativo17: > > https://bugzilla.redhat.com/show_bug.cgi?id=1834731 > > Notably: are the bitcoin.{te,fc,if} files are sane? > Are they

Re: Docker/Moby 20.10.0 has been released with cgroup v2 support

2020-12-14 Thread Daniel Walsh
On 12/13/20 09:27, Neal Gompa wrote: Hey all, It seems that Docker/Moby 20.10.0 has been released last week. With this release, Docker/Moby now fully supports cgroup v2, which means Fedora CoreOS can finally switch to cgroup v2 like the rest of Fedora has since Fedora 31. There seems to be a

Trying to setup some tmpfiles handling for podman.

2020-12-10 Thread Daniel Walsh
# /tmp/podman-run-* directory can contain content for Podman containers that have run # for many days. This following line prevents systemd from removing this content. x /tmp/podman-run-* D! /run/podman X! /var/lib/cni/networks/*/last_reserved_ip* D! /var/lib/cni/networks Basically we want to

Re: systemd-resolved in a container

2020-11-20 Thread Daniel Walsh
On 11/19/20 03:06, Nikos Mavrogiannopoulos wrote: On Wed, Nov 18, 2020 at 2:23 PM Alexander Bokovoy wrote: On ke, 18 marras 2020, Nikos Mavrogiannopoulos wrote: Hi, I realized my fedora-based containers have an /etc/resolv.conf which claims it is managed by resolved, and nsswitch.conf has

Re: systemd-resolved in a container

2020-11-19 Thread Daniel Walsh
On 11/19/20 03:06, Nikos Mavrogiannopoulos wrote: On Wed, Nov 18, 2020 at 2:23 PM Alexander Bokovoy wrote: On ke, 18 marras 2020, Nikos Mavrogiannopoulos wrote: Hi, I realized my fedora-based containers have an /etc/resolv.conf which claims it is managed by resolved, and nsswitch.conf has

Container Plumbing Days call for speakers.

2021-01-27 Thread Daniel Walsh
Announcing Free Open Source Micro Virtual Conference `Container Plumbing Days` sponsored byRed Hat. March 9-10, 2021. Looking for speakers. Low level talks, from the container engine down to the OS. Not orchestrators. http://containerplumbing.org/

Community meeting today 11:00 AM EST

2021-02-02 Thread Daniel Walsh
https://podman.io/community/meeting/ https://bluejeans.com/796412039 Agenda * 11:00 -> 11:05 - Welcome! * 11:05 -> 11:20 - Podman v3.0 Overview - Matt Heon * 11:20 -> 11:30 - Podman Compose Demo - Brent Baude * 11:30 -> 11:40 - Demo’s TBD - Tom Sweeney and more?

Re: F35 Change: Make btrfs the default file system for Fedora Cloud (System-Wide Change proposal)

2021-06-09 Thread Daniel Walsh
On 6/9/21 15:53, Zbigniew Jędrzejewski-Szmek wrote: On Wed, Jun 09, 2021 at 10:29:50AM -0500, Justin Forbes wrote: On Wed, Jun 9, 2021 at 10:19 AM David Duncan wrote: On Wed, Jun 9, 2021, 4:13 AM Zbigniew Jędrzejewski-Szmek wrote: On Wed, Jun 09, 2021 at 06:52:40AM -, David Duncan

Re: F35 Change proposal: Smaller Container Base Image (remove sssd-client, util-linux, shadow-utils) (Self-Contained Change)

2021-05-21 Thread Daniel Walsh
On 5/20/21 15:58, Colin Walters wrote: On Thu, May 20, 2021, at 8:21 AM, Daniel P. Berrangé wrote: Lets say the Fedora base image is refreshed with updated RPMs on a weekly basis. Each application republishes their app containers on an arbitrarily different schedule, maybe fortnightly,

Re: F35 Change proposal: Smaller Container Base Image (remove sssd-client, util-linux, shadow-utils) (Self-Contained Change)

2021-05-20 Thread Daniel Walsh
On 5/20/21 08:21, Daniel P. Berrangé wrote: On Wed, May 19, 2021 at 04:37:55PM -0400, Daniel Walsh wrote: The sad thing with these types of slimming is that it is horrible in production use case. I often describe layered images in the form of a wedding cake, where you have a large base

Re: Fedora CoreOS stable stream now rebased to Fedora 34

2021-05-20 Thread Daniel Walsh
On 5/20/21 02:54, Clement Verna wrote: On Wed, 19 May 2021 at 13:55, Neal Gompa > wrote: On Wed, May 19, 2021 at 2:45 AM Clement Verna mailto:cve...@fedoraproject.org>> wrote: > > > > On Wed, 19 May 2021 at 06:50, Tomasz Torcz

Re: RFC: Banning bots from submitting automated koji builds

2021-06-25 Thread Daniel Walsh
On 6/25/21 16:13, Neal Gompa wrote: On Fri, Jun 25, 2021 at 3:43 PM Daniel Walsh wrote: On 6/25/21 10:25, Neal Gompa wrote: On Fri, Jun 25, 2021 at 10:15 AM Lokesh Mandvekar wrote: Hi list, I own the rhcontainerbot account. Apologies it took so long to respond to this thread. A number

Re: RFC: Banning bots from submitting automated koji builds

2021-06-25 Thread Daniel Walsh
On 6/25/21 10:25, Neal Gompa wrote: On Fri, Jun 25, 2021 at 10:15 AM Lokesh Mandvekar wrote: Hi list, I own the rhcontainerbot account. Apologies it took so long to respond to this thread. A number of legitimate concerns have been raised about the bot, so let me address those below on

Re: Current minimal base image for containers?

2021-07-11 Thread Daniel Walsh
On 7/11/21 12:14, Martin Langhoff wrote: Hi Fedora Devel, is there any current equivalent of Fedora atomic, or the super-compact RHEL-7 minimal container images? IIRC those were _really_ small (ie: ~70MB) in size, had been installed with nodocs, etc. Couldn't find a CoreOS _minimal container_

Re: F35 Change proposal: Smaller Container Base Image (remove sssd-client, util-linux, shadow-utils) (Self-Contained Change)

2021-05-19 Thread Daniel Walsh
On 5/19/21 04:34, Daniel P. Berrangé wrote: On Wed, May 19, 2021 at 09:04:08AM +0200, Clement Verna wrote: On Mon, 17 May 2021 at 16:40, Frank Ch. Eigler wrote: Daniel P. Berrangé writes: The container runtime in the host OS will have configured most mount points before the container

Re: F35 Change proposal: Smaller Container Base Image (remove sssd-client, util-linux, shadow-utils) (Self-Contained Change)

2021-04-05 Thread Daniel Walsh
On 4/3/21 02:34, Tomasz Torcz wrote: Dnia Fri, Apr 02, 2021 at 05:30:30PM -0400, Neal Gompa napisał(a): On Fri, Apr 2, 2021 at 5:18 PM Lars Seipel wrote: On Thu, Apr 01, 2021 at 02:36:48PM -0400, Neal Gompa wrote: Unless OpenShift and RKE recently changed so that containers can run as root

Re: Podman and docker compose

2021-04-13 Thread Daniel Walsh
On 4/11/21 22:10, Gwyn Ciesla via devel wrote: Have you tried podman-compose? It's in the Fedora repos. Podman APIV2 is supposed to support docker-compose, if this fails an Issue or Bugzilla should be opened.  Podman-compose is an alternative open source project for compose, which we are not

Re: Podman and docker compose

2021-04-13 Thread Daniel Walsh
Brent PTAL On 4/11/21 20:34, Sergio Belkin wrote: Hi, I'm playing around with podman and docker compose, so I've read the post at https://www.redhat.com/sysadmin/podman-docker-compose . The example with Gitea does not work, this the

Re: Podman and docker compose

2021-04-13 Thread Daniel Walsh
Brent Baude, not on this list responds: Sergio, Unfortunately Podman can not do network links. It is something we cannot support in the API nor docker-compose. Perhaps the use of the link in the yaml could be reworked not need it? On 4/12/21 01:15, Sergio Belkin wrote: El dom, 11 abr

Re: Anyone interested in helping to convert the Ubuntu Discourse Docker setup to Fedora Podman?

2021-12-07 Thread Daniel Walsh
On 12/6/21 14:11, Philip Rhoades via devel wrote: People, I cloned this:   https://github.com/discourse/discourse_docker and did a "podman build" on the Dockerfile and it made it to step 39 (of 59) before stopping with a complaint about a missing dir . . It would be great to get a Fedora

Re: F36 - Errors/Warnings with `dnf update`

2022-03-31 Thread Daniel Walsh
On 3/31/22 02:35, Carmelo Sarta wrote: Hello there! I've never seen this error before `error: Plugin selinux: hook fsm_file_prepare failed` but I would try `dnf reinstall container-selinux` and maybe `dnf reinstall podman` There seems to be an error appening when people are installing

Re: shadow-utils libsubid soname bump

2022-01-27 Thread Daniel Walsh
possible. The update can wait until the change is accepted for F36. We'll need to coordinate to do the two builds, though. Can you please ping me when everything is ready on your side? @Daniel Walsh <mailto:dwa...@redhat.com> : yes, the API provided by the shared library has changed it

Podman 4.0 rc2 is available in updates-testing.

2022-01-24 Thread Daniel Walsh
We would love to have people play with this and test it out. Note: this release has breaking changes to it's API, so it will not be released to f35. Only to F36, but users will be able to download and use it on F35, we will not push it to stable though.

  1   2   >