如何在Containerfile中配置容器启动时自动启动systemd Podman服务?
在容器内自动启动systemd管理的Podman服务
问题说明
我通过podman build -t amazing-stuff-007:001 .构建了一个包含Podman的systemd-fedora镜像,目前可以手动在容器内启动Podman socket,但无法实现容器启动时自动通过systemd拉起Podman服务,需要可行的配置方案。
对应的原始Containerfile如下:
# stable/Containerfile # # Build a Podman container image from the latest # stable version of Podman on the Fedoras Updates System. # https://bodhi.fedoraproject.org/updates/?search=podman # This image can be used to create a secured container # that runs safely with privileges within the container. # FROM docker.io/jrei/systemd-fedora:latest # Don't include container-selinux and remove # directories used by dnf that are just taking # up space. # TODO: rpm --setcaps... needed due to Fedora (base) image builds # being (maybe still?) affected by # https://bugzilla.redhat.com/show_bug.cgi?id=1995337#c3 RUN dnf -y update && \ rpm --setcaps shadow-utils 2>/dev/null && \ dnf -y install podman fuse-overlayfs openssh-clients \ --exclude container-selinux && \ dnf clean all && \ rm -rf /var/cache /var/log/dnf* /var/log/yum.* RUN useradd podman; \ echo -e "podman:1:999 podman:1001:64535" > /etc/subuid; \ echo -e "podman:1:999 podman:1001:64535" > /etc/subgid; \ podman system migrate; ARG _REPO_URL="https://raw.githubusercontent.com/containers/image_build/main/podman" ADD $_REPO_URL/containers.conf /etc/containers/containers.conf ADD $_REPO_URL/podman-containers.conf /home/podman/.config/containers/containers.conf RUN mkdir -p /home/podman/.local/share/containers && \ chown podman:podman -R /home/podman && \ chmod 644 /etc/containers/containers.conf # Copy & modify the defaults to provide reference if runtime changes needed. # Changes here are required for running with fuse-overlay storage inside container. RUN sed -e 's|^#mount_program|mount_program|g' \ -e '/additionalimage.*/a "/var/lib/shared",' \ -e 's|^mountopt[[:space:]]*=.*$|mountopt = "nodev,fsync=0"|g' \ /usr/share/containers/storage.conf \ > /etc/containers/storage.conf # Setup internal Podman to pass subscriptions down from host to internal container RUN printf '/run/secrets/etc-pki-entitlement:/run/secrets/etc-pki-entitlement /run/secrets/rhsm:/run/secrets/rhsm ' > /etc/containers/mounts.conf # Note VOLUME options must always happen after the chown call above # RUN commands can not modify existing volumes VOLUME /var/lib/containers VOLUME /home/podman/.local/share/containers RUN mkdir -p /var/lib/shared/overlay-images \ /var/lib/shared/overlay-layers \ /var/lib/shared/vfs-images \ /var/lib/shared/vfs-layers && \ touch /var/lib/shared/overlay-images/images.lock && \ touch /var/lib/shared/overlay-layers/layers.lock && \ touch /var/lib/shared/vfs-images/images.lock && \ touch /var/lib/shared/vfs-layers/layers.lock ENV _CONTAINERS_USERNS_CONFIGURED="" ENTRYPOINT /lib/systemd/systemd
当前启动容器命令:
podman run -d --name systemd-fedora --tmpfs /tmp --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro cbfcbc44a695
可行配置方案
要实现容器启动时自动通过systemd启动Podman服务,需配置用户级systemd服务(适配无根Podman场景),具体修改如下:
1. 修改Containerfile,添加自动启动配置
在现有Containerfile的末尾(ENTRYPOINT之前)添加以下内容:
# 启用podman用户的linger模式,确保用户级systemd在未登录时也能运行 RUN loginctl enable-linger podman && \ # 切换到podman用户,启用podman.socket服务(systemd会自动关联启动podman.service) su - podman -c "systemctl --user enable podman.socket" && \ # 配置系统级systemd在启动时激活podman用户的systemd实例 mkdir -p /etc/systemd/system/user@.service.d && \ printf '[Service]\nExecStart=\nExecStart=-/usr/lib/systemd/systemd --user\n' > /etc/systemd/system/user@.service.d/override.conf
2. 重新构建镜像
执行原构建命令重新生成镜像:
podman build -t amazing-stuff-007:001 .
3. 启动容器(保持原有命令即可)
原启动命令无需修改,容器启动后systemd会自动触发podman用户的podman.socket服务,进而自动启动podman.service:
podman run -d --name systemd-fedora --tmpfs /tmp --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro amazing-stuff-007:001
验证方法
进入容器后,执行以下命令确认服务状态:
# 进入容器 podman exec -it systemd-fedora su - podman # 查看用户级Podman服务状态 systemctl --user status podman.service
如果服务显示active (running),说明配置生效。
内容的提问来源于stack exchange,提问作者Jo Vanmont
相关产品推荐
相关产品推荐

