coreos / fedora-coreos-tracker

Issue tracker for Fedora CoreOS
https://fedoraproject.org/coreos/
264 stars 59 forks source link

Fedora 40 Changes: Podman v5 #1629

Closed jlebon closed 6 months ago

jlebon commented 11 months ago

The podman team is planning to rebase to v5 in Fedora 40: https://fedoraproject.org/wiki/Changes/Podman5.

This includes a few breaking changes.

We'll need to communicate this and include links to steps on how to adapt existing nodes.

jlebon commented 11 months ago

We moved to cgroups v2 by default in f34 and to netavark in f36. So anyone who's reprovisioned since f36 shouldn't be affected by this.

For anyone else, they will need to either reprovision with newer bootimages, or:

dustymabe commented 11 months ago

We discussed this in the community meeting today.

12:09:29*  dustymabe | !info as soon as the podman v5 change gets accepted for Fedora 40 we should add CLHM helpers to
                     | notifiy people of the incoming changes and also a coreos-status post with the details
dustymabe commented 10 months ago

This has now been accepted

gursewak1997 commented 9 months ago

Also, Podman v5 doesn't ship podman-plugins rpm anymore which is expected considering the drop of support for CNI networking entirely. Also, containernetworking-plugins was dropped as a dependency of podman but we explicitly pulled that in for upgrading nodes that were using CNI networking. We wouldn't need that anymore. So, we will have to remove them from our manifest. Relevant commits:

dustymabe commented 9 months ago

ok so we can drop podman-plugins and containernetworking-plugins from our manifest since they are in support of CNI networking which is no longer supported in Podman v5.

From:

core@apu2:~$ rpm -qi podman-plugins 
Name        : podman-plugins
Epoch       : 5
Version     : 4.8.3
Release     : 1.fc39
Architecture: x86_64
Install Date: Mon Feb  5 22:41:36 2024
Group       : Unspecified
Size        : 3701652
License     : Apache-2.0 AND BSD-2-Clause AND BSD-3-Clause AND ISC AND MIT AND MPL-2.0
Signature   : RSA/SHA256, Wed Jan  3 14:21:29 2024, Key ID 75cf5ac418b8e74c
Source RPM  : podman-4.8.3-1.fc39.src.rpm
Build Date  : Wed Jan  3 14:11:33 2024
Build Host  : buildvm-x86-20.iad2.fedoraproject.org
Packager    : Fedora Project
Vendor      : Fedora Project
URL         : https://podman.io/
Bug URL     : https://bugz.fedoraproject.org/podman
Summary     : Plugins for podman
Description :
This plugin sets up the use of dnsmasq on a given CNI network so
that Pods can resolve each other by name.  When configured,
the pod and its IP address are added to a network specific hosts file
that dnsmasq will read in.  Similarly, when a pod
is removed from the network, it will remove the entry from the hosts
file.  Each CNI network will have its own dnsmasq instance.

That explains why dnsmasq is there too on that line in the config. I would say we could remove it but... we do have docs that mention it being used for both podman and NetworkManager so we can't just remove it but we can update the docs to drop the podman reference and update the comment in the manifest to mention NetworkManager.

gursewak1997 commented 8 months ago

We've incorporated CLHM helpers to inform individuals about upcoming changes. Additionally, we've removed the inclusion of containernetworking-plugins and podman-plugins. If there's anything additional needed regarding the Podman v5 changes, please feel free to open this issue.

dustymabe commented 8 months ago

In the meeting https://github.com/coreos/fedora-coreos-tracker/issues/1629#issuecomment-1854644851 we said we'd do a coreos-status post. I think that still needs to happen.

travier commented 8 months ago

https://discussion.fedoraproject.org/t/switching-from-cni-to-netavark-on-fedora-coreos-non-destructively/106594 > This sounds like a great question that we would need an answer to.

https://discussion.fedoraproject.org/t/switching-from-cni-to-netavark-on-fedora-coreos-non-destructively/106594/4

travier commented 7 months ago

I've just successfully converted a system that was using "ephemeral" containers (i.e. running using --rm and storing everything in volumes bind mounts, not podman volumes). It "still" needed conversion even though no volumes where used and the containers and networks were created fresh on boot (using quadlets).

Stopping all containers, running podman system reset --force and rebooting worked well.

travier commented 7 months ago

An option in podman system reset to remove all networks, containers but not volumes would be nice and would likely help for https://discussion.fedoraproject.org/t/switching-from-cni-to-netavark-on-fedora-coreos-non-destructively/106594 as it's likely the most common case.

travier commented 7 months ago

More Links:

dustymabe commented 7 months ago

The fix for this went into next stream release 40.20240322.1.0. Please try out the new release and report issues.

dustymabe commented 6 months ago

The fix for this went into testing stream release 40.20240416.2.0. Please try out the new release and report issues.

dustymabe commented 6 months ago

The fix for this went into stable stream release 40.20240416.3.1.