'\" t .nh .TH podman-systemd.unit 5 .SH NAME .PP podman-systemd.unit - systemd units using Podman Quadlet .SH SYNOPSIS .PP \fIname\fP\&.container, \fIname\fP\&.volume, \fIname\fP\&.network, \fIname\fP\&.kube \fIname\fP\&.image, \fIname\fP\&.build \fIname\fP\&.pod .SS Podman rootful unit search path .PP Quadlet files for the root user can be placed in the following two directories: .RS .IP \(bu 2 /etc/containers/systemd/ .IP \(bu 2 /usr/share/containers/systemd/ .RE .SS Podman rootless unit search path .PP Quadlet files for non-root users can be placed in the following directories .RS .IP \(bu 2 $XDG_CONFIG_HOME/containers/systemd/ or ~/.config/containers/systemd/ .IP \(bu 2 /etc/containers/systemd/users/$(UID) .IP \(bu 2 /etc/containers/systemd/users/ .RE .SS Using symbolic links .PP Quadlet supports using symbolic links for the base of the search paths. Symbolic links below the search paths are not supported. .SH DESCRIPTION .PP Podman supports building, and starting containers (and creating volumes) via systemd by using a systemd generator. These files are read during boot (and when \fBsystemctl daemon-reload\fR is run) and generate corresponding regular systemd service unit files. Both system and user systemd units are supported. All options and tables available in standard systemd unit files are supported. For example, options defined in the [Service] table and [Install] tables pass directly to systemd and are handled by it. See systemd.unit(5) man page for more information. .PP The Podman generator reads the search paths above and reads files with the extensions \fB\&.container\fR \fB\&.volume\fR, \fB\&.network\fR, \fB\&.build\fR, \fB\&.pod\fR and \fB\&.kube\fR, and for each file generates a similarly named \fB\&.service\fR file. Be aware that existing vendor services (i.e., in \fB/usr/\fR) are replaced if they have the same name. The generated unit files can be started and managed with \fBsystemctl\fR like any other systemd service. \fBsystemctl {--user} list-unit-files\fR lists existing unit files on the system. .PP The Podman files use the same format as regular systemd unit files. Each file type has a custom section (for example, \fB[Container]\fR) that is handled by Podman, and all other sections are passed on untouched, allowing the use of any normal systemd configuration options like dependencies or cgroup limits. .PP The source files also support drop-ins in the same way systemd does. For a given source file (\fBfoo.container\fR), the corresponding \fB\&.d\fR directory (\fBfoo.container.d\fR) will be scanned for files with a \fB\&.conf\fR extension, which are then merged into the base file in alphabetical order. Top-level type drop-ins (\fBcontainer.d\fR) will also be included. If the unit contains dashes ("-") in the name (\fBfoo-bar-baz.container\fR), then the drop-in directories generated by truncating the name after the dash are searched as well (\fBfoo-.container.d\fR and \fBfoo-bar-.container.d\fR). Drop-in files with the same name further down the hierarchy override those further up (\fBfoo-bar-baz.container.d/10-override.conf\fR overrides \fBfoo-bar-.container.d/10-override.conf\fR, which overrides \fBfoo-.service.d/10-override.conf\fR, which overrides \fBcontainer.d/10-override.conf\fR). The format of these drop-in files is the same as the base file. This is useful to alter or add configuration settings for a unit, without having to modify unit files. .PP For rootless containers, when administrators place Quadlet files in the /etc/containers/systemd/users directory, all users' sessions execute the Quadlet when the login session begins. If the administrator places a Quadlet file in the /etc/containers/systemd/users/${UID}/ directory, then only the user with the matching UID execute the Quadlet when the login session gets started. For unit files placed in subdirectories within /etc/containers/systemd/user/${UID}/ and the other user unit search paths, Quadlet will recursively search and run the unit files present in these subdirectories. .PP Note: When a Quadlet is starting, Podman often pulls or builds one more container images which may take a considerable amount of time. Systemd defaults service start time to 90 seconds, or fails the service. Pre-pulling the image or extending the systemd timeout time for the service using the \fITimeoutStartSec\fP Service option can fix the problem. A word of caution: \fITimeoutStartSec\fP is not available for \fBType=oneshot\fR units. Refer to \fBsystemd.service(5)\fR for more information on how to handle long startup times for units which do not need to stay active once their main process has finished. .PP Adding the following snippet to a Quadlet file extends the systemd timeout to 15 minutes. .EX [Service] TimeoutStartSec=900 .EE .PP Quadlet requires the use of cgroup v2, use \fBpodman info --format {{.Host.CgroupsVersion}}\fR to check on the system. .SS Service Type .PP By default, the \fBType\fR field of the \fBService\fR section of the Quadlet file does not need to be set. Quadlet will set it to \fBnotify\fR for \fB\&.container\fR and \fB\&.kube\fR files, \fBforking\fR for \fB\&.pod\fR files, and \fBoneshot\fR for \fB\&.volume\fR, \fB\&.network\fR, \fB\&.build\fR, and \fB\&.image\fR files. .PP However, \fBType\fR may be explicitly set to \fBoneshot\fR for \fB\&.container\fR and \fB\&.kube\fR files when no containers are expected to run once \fBpodman\fR exits. .PP When setting \fBType=oneshot\fR, it is recommended to also set \fBRemainAfterExit=yes\fR to prevent the service state from becoming \fBinactive (dead)\fR\&. However, when activating a service via a timer unit, having \fBRemainAfterExit=yes\fR leaves the job in a "started" state which prevents subsequent activations by the timer. For more information, see the \fBsystemd.service(5)\fR man page. .PP Examples for such cases: - \fB\&.container\fR file with an image that exits after their entrypoint has finished `\fB -\fR\&.kube` file pointing to a Kubernetes Yaml file that does not define any containers. E.g. PVCs only .SS Enabling unit files .PP The services created by Podman are considered transient by systemd, which means they don't have the same persistence rules as regular units. In particular, it is not possible to "systemctl enable" them in order for them to become automatically enabled on the next boot. .PP To compensate for this, the generator manually applies the \fB[Install]\fR section of the container definition unit files during generation, in the same way \fBsystemctl enable\fR does when run later. .PP For example, to start a container on boot, add something like this to the file: .EX [Install] WantedBy=default.target .EE .PP Currently, only the \fBAlias\fR, \fBWantedBy\fR and \fBRequiredBy\fR keys are supported. .PP The Install section can be part of the main file, or it can be in a separate drop-in file as described above. The latter allows you to install an non-enabled unit and then later enabling it by installing the drop-in. .PP \fBNOTE:\fP To express dependencies between containers, use the generated names of the service. In other words \fBWantedBy=other.service\fR, not \fBWantedBy=other.container\fR\&. The same is true for other kinds of dependencies, too, like \fBAfter=other.service\fR\&. .SS Template files .PP Systemd supports a concept of template files. They are units with names of the form "basename@instancename.service" when they are running, but that can be instantiated multiple times from a single "basename@.service" file. The individual instances can also be different by using drop-in files with the full instance name. .PP Quadlets support these in two ways. First of all, a quadlet unit with a template form will generate a systemd service with a template form, and the template systemd service can be used as a regular template. For example, "foo@.container" will generate "foo@.service" and you can then "systemctl start foo@bar.service". .PP Secondly, if you make a symlink like "foo@instance.container", that will generate an instantiated template file. When generating this file quadlet will read drop-in files both from the instanced directory (foo@instance.container.d) and the template directory (foo@.container.d). This allows customization of individual instances. .PP Instanced template files (like \fBfoo@bar.container\fR) can be enabled just like non-templated ones. However, templated ones (\fBfoo@.container\fR) are different, because they need to be instantiated. If the \fB[Install]\fR section contains a \fBDefaultInstance=\fR key, then that instance will be enabled, but if not, nothing will happen and the options will only be used as the default for units that are instantiated using symlinks. .PP An example template file \fBsleep@.container\fR might look like this: .EX [Unit] Description=A templated sleepy container [Container] Image=quay.io/fedora/fedora Exec=sleep %i [Service] # Restart service when sleep finishes Restart=always [Install] WantedBy=multi-user.target DefaultInstance=100 .EE .PP If this is installed, then on boot there will be a \fBsleep@100.service\fR running that sleeps for 100 seconds. You can then do something like \fBsystemctl start sleep@50.service\fR to start another instance that sleeps 50 seconds, or alternatively another service can start it via a dependency like \fBWants=sleep@50.service\fR\&. .PP In addition, if you do \fBln -s sleep@.container sleep@10.container\fR you will also have a 10 second sleep running at boot. And, if you want that particular instance to be running with another image, you can create a drop-in file like \fBsleep@10.container.d/10-image.conf\fR: .EX [Container] Image=quay.io/centos/centos .EE .SS Relative paths .PP In order to support Systemd specifiers, Quadlet does not resolve relative paths that start with \fB%\fR\&. To resolve such a path, prepend it with \fB\&./\fR\&. .PP For example, instead of \fBEnvironmentFile=%n/env\fR use \fBEnvironmentFile=./%n/env\fR .SS Debugging unit files .PP After placing the unit file in one of the unit search paths (mentioned above), you can start it with \fBsystemctl start {--user}\fR\&. If it fails with "Failed to start example.service: Unit example.service not found.", then it is possible that you used incorrect syntax or you used an option from a newer version of Podman Quadlet and the generator failed to create a service file. .PP View the generated files and/or error messages with: .EX /usr/lib/systemd/system-generators/podman-system-generator {--user} --dryrun .EE .SS Debugging a limited set of unit files .PP If you would like to debug a limited set of unit files, you can copy them to a separate directory and set the \fBQUADLET_UNIT_DIRS\fR environment variable to this directory when running the command below: .EX QUADLET_UNIT_DIRS= /usr/lib/systemd/system-generators/podman-system-generator {--user} --dryrun .EE .PP This will instruct Quadlet to look for units in this directory instead of the common ones and by that limit the output to only the units you are debugging. .SH Container units [Container] .PP Container units are named with a \fB\&.container\fR extension and contain a \fB[Container]\fR section describing the container that is run as a service. The resulting service file contains a line like \fBExecStart=podman run … image-name\fR, and most of the keys in this section control the command-line options passed to Podman. However, some options also affect the details of how systemd is set up to run and interact with the container. .PP By default, the Podman container has the same name as the unit, but with a \fBsystemd-\fR prefix, i.e. a \fB$name.container\fR file creates a \fB$name.service\fR unit and a \fBsystemd-$name\fR Podman container. The \fBContainerName\fR option allows for overriding this default name with a user-provided one. .PP There is only one required key, \fBImage\fR, which defines the container image the service runs. .PP Valid options for \fB[Container]\fR are listed below: .TS allbox; l l l l . \fB\fB[Container] options\fP\fP \fB\fBpodman run equivalent\fP\fP AddCapability=CAP --cap-add CAP AddDevice=/dev/foo --device /dev/foo Annotation="XYZ" --annotation "XYZ" AutoUpdate=registry T{ --label "io.containers.autoupdate=registry" T} ContainerName=name --name name ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf DNS=192.168.55.1 --dns=192.168.55.1 DNSOption=ndots:1 --dns-option=ndots:1 DNSSearch=foo.com --dns-search=foo.com DropCapability=CAP --cap-drop=CAP Entrypoint=/foo.sh --entrypoint=/foo.sh Environment=foo=bar --env foo=bar EnvironmentFile=/tmp/env --env-file /tmp/env EnvironmentHost=true --env-host Exec=/usr/bin/command T{ Command after image specification - /usr/bin/command T} ExposeHostPort=50-59 --expose 50-59 GIDMap=0:10000:10 --gidmap=0:10000:10 GlobalArgs=--log-level=debug --log-level=debug Group=1234 --user UID:1234 GroupAdd=keep-groups --group-add=keep-groups HealthCmd=/usr/bin/command --health-cmd=/usr/bin/command HealthInterval=2m --health-interval=2m HealthOnFailure=kill --health-on-failure=kill HealthRetries=5 --health-retries=5 HealthStartPeriod=1m T{ --health-start-period=period=1m T} HealthStartupCmd=command --health-startup-cmd=command HealthStartupInterval=1m --health-startup-interval=1m HealthStartupRetries=8 --health-startup-retries=8 HealthStartupSuccess=2 --health-startup-success=2 HealthStartupTimeout=1m33s --health-startup-timeout=1m33s HealthTimeout=20s --health-timeout=20s HostName=new-host-name --hostname="new-host-name" Image=ubi8 Image specification - ubi8 IP=192.5.0.1 --ip 192.5.0.1 IP6=2001:db8::1 --ip6 2001:db8::1 Label="XYZ" --label "XYZ" LogDriver=journald --log-driver journald LogOpt=path=/var/log/mykube\&.json --log-opt path=/var/log/mykube\&.json Mask=/proc/sys/foo:/proc/sys/bar T{ --security-opt mask=/proc/sys/foo:/proc/sys/bar T} Mount=type=... --mount type=... Network=host --net host NetworkAlias=name --network-alias name NoNewPrivileges=true T{ --security-opt no-new-privileges T} Notify=true --sdnotify container PidsLimit=10000 --pids-limit 10000 Pod=pod-name --pod=pod-name PodmanArgs=--add-host foobar --add-host foobar PublishPort=50-59 --publish 50-59 Pull=never --pull=never ReadOnly=true --read-only ReadOnlyTmpfs=true --read-only-tmpfs Rootfs=/var/lib/rootfs --rootfs /var/lib/rootfs RunInit=true --init SeccompProfile=/tmp/s.json T{ --security-opt seccomp=/tmp/s.json T} Secret=secret --secret=secret[,opt=opt ...] SecurityLabelDisable=true --security-opt label=disable SecurityLabelFileType=usr_t T{ --security-opt label=filetype:usr_t T} SecurityLabelLevel=s0:c1,c2 T{ --security-opt label=level:s0:c1,c2 T} SecurityLabelNested=true --security-opt label=nested SecurityLabelType=spc_t T{ --security-opt label=type:spc_t T} ShmSize=100m --shm-size=100m StopSignal=SIGINT --stop-signal=SIGINT StopTimeout=20 --stop-timeout=20 SubGIDMap=gtest --subgidname=gtest SubUIDMap=utest --subuidname=utest Sysctl=name=value --sysctl=name=value Timezone=local --tz local Tmpfs=/work --tmpfs /work UIDMap=0:10000:10 --uidmap=0:10000:10 Ulimit=nofile=1000:10000 --ulimit nofile=1000:10000 Unmask=ALL --security-opt unmask=ALL User=bin --user bin UserNS=keep-id:uid=200,gid=210 T{ --userns keep-id:uid=200,gid=210 T} Volume=/source:/dest --volume /source:/dest WorkingDir=$HOME --workdir $HOME .TE .PP Description of \fB[Container]\fR section are: .SS \fBAddCapability=\fR .PP Add these capabilities, in addition to the default Podman capability set, to the container. .PP This is a space separated list of capabilities. This key can be listed multiple times. .PP For example: .EX AddCapability=CAP_DAC_OVERRIDE CAP_IPC_OWNER .EE .SS \fBAddDevice=\fR .PP Adds a device node from the host into the container. The format of this is \fBHOST-DEVICE[:CONTAINER-DEVICE][:PERMISSIONS]\fR, where \fBHOST-DEVICE\fR is the path of the device node on the host, \fBCONTAINER-DEVICE\fR is the path of the device node in the container, and \fBPERMISSIONS\fR is a list of permissions combining 'r' for read, \&'w' for write, and 'm' for mknod(2). The \fB-\fR prefix tells Quadlet to add the device only if it exists on the host. .PP This key can be listed multiple times. .SS \fBAnnotation=\fR .PP Set one or more OCI annotations on the container. The format is a list of \fBkey=value\fR items, similar to \fBEnvironment\fR\&. .PP This key can be listed multiple times. .SS \fBAutoUpdate=\fR .PP Indicates whether the container will be auto-updated (podman-auto-update(1)). The following values are supported: .RS .IP \(bu 2 \fBregistry\fR: Requires a fully-qualified image reference (e.g., quay.io/podman/stable:latest) to be used to create the container. This enforcement is necessary to know which image to actually check and pull. If an image ID was used, Podman does not know which image to check/pull anymore. .IP \(bu 2 \fBlocal\fR: Tells Podman to compare the image a container is using to the image with its raw name in local storage. If an image is updated locally, Podman simply restarts the systemd unit executing the container. .RE .SS \fBContainerName=\fR .PP The (optional) name of the Podman container. If this is not specified, the default value of \fBsystemd-%N\fR is used, which is the same as the service name but with a \fBsystemd-\fR prefix to avoid conflicts with user-managed containers. .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBDNS=\fR .PP Set network-scoped DNS resolver/nameserver for containers in this network. .PP This key can be listed multiple times. .SS \fBDNSOption=\fR .PP Set custom DNS options. .PP This key can be listed multiple times. .SS \fBDNSSearch=\fR .PP Set custom DNS search domains. Use \fBDNSSearch=.\fP to remove the search domain. .PP This key can be listed multiple times. .SS \fBDropCapability=\fR .PP Drop these capabilities from the default podman capability set, or \fBall\fR to drop all capabilities. .PP This is a space separated list of capabilities. This key can be listed multiple times. .PP For example: .EX DropCapability=CAP_DAC_OVERRIDE CAP_IPC_OWNER .EE .SS \fBEntrypoint=\fR .PP Override the default ENTRYPOINT from the image. Equivalent to the Podman \fB--entrypoint\fR option. Specify multi option commands in the form of a json string. .SS \fBEnvironment=\fR .PP Set an environment variable in the container. This uses the same format as services in systemd and can be listed multiple times. .SS \fBEnvironmentFile=\fR .PP Use a line-delimited file to set environment variables in the container. The path may be absolute or relative to the location of the unit file. This key may be used multiple times, and the order persists when passed to \fBpodman run\fR\&. .SS \fBEnvironmentHost=\fR .PP Use the host environment inside of the container. .SS \fBExec=\fR .PP If this is set then it defines what command line to run in the container. If it is not set the default entry point of the container image is used. The format is the same as for systemd command lines. .SS \fBExposeHostPort=\fR .PP Exposes a port, or a range of ports (e.g. \fB50-59\fR), from the host to the container. Equivalent to the Podman \fB--expose\fR option. .PP This key can be listed multiple times. .SS \fBGIDMap=\fR .PP Run the container in a new user namespace using the supplied GID mapping. Equivalent to the Podman \fB--gidmap\fR option. .PP This key can be listed multiple times. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBrun\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBGroup=\fR .PP The (numeric) GID to run as inside the container. This does not need to match the GID on the host, which can be modified with \fBUsersNS\fR, but if that is not specified, this GID is also used on the host. .SS \fBGroupAdd=\fR .PP Assign additional groups to the primary user running within the container process. Also supports the \fBkeep-groups\fR special flag. Equivalent to the Podman \fB--group-add\fR option. .SS \fBHealthCmd=\fR .PP Set or alter a healthcheck command for a container. A value of none disables existing healthchecks. Equivalent to the Podman \fB--health-cmd\fR option. .SS \fBHealthInterval=\fR .PP Set an interval for the healthchecks. An interval of disable results in no automatic timer setup. Equivalent to the Podman \fB--health-interval\fR option. .SS \fBHealthOnFailure=\fR .PP Action to take once the container transitions to an unhealthy state. The "kill" action in combination integrates best with systemd. Once the container turns unhealthy, it gets killed, and systemd restarts the service. Equivalent to the Podman \fB--health-on-failure\fR option. .SS \fBHealthRetries=\fR .PP The number of retries allowed before a healthcheck is considered to be unhealthy. Equivalent to the Podman \fB--health-retries\fR option. .SS \fBHealthStartPeriod=\fR .PP The initialization time needed for a container to bootstrap. Equivalent to the Podman \fB--health-start-period\fR option. .SS \fBHealthStartupCmd=\fR .PP Set a startup healthcheck command for a container. Equivalent to the Podman \fB--health-startup-cmd\fR option. .SS \fBHealthStartupInterval=\fR .PP Set an interval for the startup healthcheck. An interval of disable results in no automatic timer setup. Equivalent to the Podman \fB--health-startup-interval\fR option. .SS \fBHealthStartupRetries=\fR .PP The number of attempts allowed before the startup healthcheck restarts the container. Equivalent to the Podman \fB--health-startup-retries\fR option. .SS \fBHealthStartupSuccess=\fR .PP The number of successful runs required before the startup healthcheck succeeds and the regular healthcheck begins. Equivalent to the Podman \fB--health-startup-success\fR option. .SS \fBHealthStartupTimeout=\fR .PP The maximum time a startup healthcheck command has to complete before it is marked as failed. Equivalent to the Podman \fB--health-startup-timeout\fR option. .SS \fBHealthTimeout=\fR .PP The maximum time allowed to complete the healthcheck before an interval is considered failed. Equivalent to the Podman \fB--health-timeout\fR option. .SS \fBHostName=\fR .PP Sets the host name that is available inside the container. Equivalent to the Podman \fB--hostname\fR option. .SS \fBImage=\fR .PP The image to run in the container. It is recommended to use a fully qualified image name rather than a short name, both for performance and robustness reasons. .PP The format of the name is the same as when passed to \fBpodman pull\fR\&. So, it supports using \fB:tag\fR or digests to guarantee the specific image version. .PP As a special case, if the \fBname\fR of the image ends with \fB\&.image\fR, Quadlet will use the image pulled by the corresponding \fB\&.image\fR file, and the generated systemd service contains a dependency on the \fB$name-image.service\fR\&. Note that the corresponding \fB\&.image\fR file must exist. .SS \fBIP=\fR .PP Specify a static IPv4 address for the container, for example \fB10.88.64.128\fP\&. Equivalent to the Podman \fB--ip\fR option. .SS \fBIP6=\fR .PP Specify a static IPv6 address for the container, for example \fBfd46:db93:aa76:ac37::10\fP\&. Equivalent to the Podman \fB--ip6\fR option. .SS \fBLabel=\fR .PP Set one or more OCI labels on the container. The format is a list of \fBkey=value\fR items, similar to \fBEnvironment\fR\&. .PP This key can be listed multiple times. .SS \fBLogDriver=\fR .PP Set the log-driver used by Podman when running the container. Equivalent to the Podman \fB--log-driver\fR option. .SS \fBLogOpt=\fR .PP Set the log-opt (logging options) used by Podman when running the container. Equivalent to the Podman \fB--log-opt\fR option. This key can be listed multiple times. .SS \fBMask=\fR .PP Specify the paths to mask separated by a colon. \fBMask=/path/1:/path/2\fR\&. A masked path cannot be accessed inside the container. .SS \fBMount=\fR .PP Attach a filesystem mount to the container. This is equivalent to the Podman \fB--mount\fR option, and generally has the form \fBtype=TYPE,TYPE-SPECIFIC-OPTION[,...]\fR\&. .PP As a special case, for \fBtype=volume\fR if \fBsource\fR ends with \fB\&.volume\fR, a Podman named volume called \fBsystemd-$name\fR is used as the source, and the generated systemd service contains a dependency on the \fB$name-volume.service\fR\&. Such a volume can be automatically be lazily created by using a \fB$name.volume\fR Quadlet file. .PP This key can be listed multiple times. .SS \fBNetwork=\fR .PP Specify a custom network for the container. This has the same format as the \fB--network\fR option to \fBpodman run\fR\&. For example, use \fBhost\fR to use the host network in the container, or \fBnone\fR to not set up networking in the container. .PP As a special case, if the \fBname\fR of the network ends with \fB\&.network\fR, a Podman network called \fBsystemd-$name\fR is used, and the generated systemd service contains a dependency on the \fB$name-network.service\fR\&. Such a network can be automatically created by using a \fB$name.network\fR Quadlet file. .PP This key can be listed multiple times. .SS \fBNetworkAlias=\fR .PP Add a network-scoped alias for the container. This has the same format as the \fB--network-alias\fR option to \fBpodman run\fR\&. Aliases can be used to group containers together in DNS resolution: for example, setting \fBNetworkAlias=web\fR on multiple containers will make a DNS query for \fBweb\fR resolve to all the containers with that alias. .PP This key can be listed multiple times. .SS \fBNoNewPrivileges=\fR (defaults to \fBfalse\fR) .PP If enabled, this disables the container processes from gaining additional privileges via things like setuid and file capabilities. .SS \fBNotify=\fR (defaults to \fBfalse\fR) .PP By default, Podman is run in such a way that the systemd startup notify command is handled by the container runtime. In other words, the service is deemed started when the container runtime starts the child in the container. However, if the container application supports sd_notify, then setting \fBNotify\fR to true passes the notification details to the container allowing it to notify of startup on its own. .PP In addition, setting \fBNotify\fR to \fBhealthy\fR will postpone startup notifications until such time as the container is marked healthy, as determined by Podman healthchecks. Note that this requires setting up a container healthcheck, see the \fBHealthCmd\fR option for more. .SS \fBPidsLimit=\fR .PP Tune the container's pids limit. This is equivalent to the Podman \fB--pids-limit\fR option. .SS \fBPod=\fR .PP Specify a Quadlet \fB\&.pod\fR unit to link the container to. The value must take the form of \fB.pod\fR and the \fB\&.pod\fR unit must exist. .PP Quadlet will add all the necessary parameters to link between the container and the pod and between their corresponding services. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman run\fR command in the generated file (right before the image name in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBPublishPort=\fR .PP Exposes a port, or a range of ports (e.g. \fB50-59\fR), from the container to the host. Equivalent to the Podman \fB--publish\fR option. The format is similar to the Podman options, which is of the form \fBip:hostPort:containerPort\fR, \fBip::containerPort\fR, \fBhostPort:containerPort\fR or \fBcontainerPort\fR, where the number of host and container ports must be the same (in the case of a range). .PP If the IP is set to 0.0.0.0 or not set at all, the port is bound on all IPv4 addresses on the host; use [::] for IPv6. .PP Note that not listing a host port means that Podman automatically selects one, and it may be different for each invocation of service. This makes that a less useful option. The allocated port can be found with the \fBpodman port\fR command. .PP This key can be listed multiple times. .SS \fBPull=\fR .PP Set the image pull policy. This is equivalent to the Podman \fB--pull\fR option .SS \fBReadOnly=\fR (defaults to \fBfalse\fR) .PP If enabled, makes the image read-only. .SS \fBReadOnlyTmpfs=\fR (defaults to \fBtrue\fR) .PP If ReadOnly is set to \fBtrue\fR, mount a read-write tmpfs on /dev, /dev/shm, /run, /tmp, and /var/tmp. .SS \fBRootfs=\fR .PP The rootfs to use for the container. Rootfs points to a directory on the system that contains the content to be run within the container. This option conflicts with the \fBImage\fR option. .PP The format of the rootfs is the same as when passed to \fBpodman run --rootfs\fR, so it supports overlay mounts as well. .PP Note: On SELinux systems, the rootfs needs the correct label, which is by default unconfined_u:object_r:container_file_t:s0. .SS \fBRunInit=\fR (default to \fBfalse\fR) .PP If enabled, the container has a minimal init process inside the container that forwards signals and reaps processes. .SS \fBSeccompProfile=\fR .PP Set the seccomp profile to use in the container. If unset, the default podman profile is used. Set to either the pathname of a json file, or \fBunconfined\fR to disable the seccomp filters. .SS \fBSecret=\fR .PP Use a Podman secret in the container either as a file or an environment variable. This is equivalent to the Podman \fB--secret\fR option and generally has the form \fBsecret[,opt=opt ...]\fR .SS \fBSecurityLabelDisable=\fR .PP Turn off label separation for the container. .SS \fBSecurityLabelFileType=\fR .PP Set the label file type for the container files. .SS \fBSecurityLabelLevel=\fR .PP Set the label process level for the container processes. .SS \fBSecurityLabelNested=\fR .PP Allow SecurityLabels to function within the container. This allows separation of containers created within the container. .SS \fBSecurityLabelType=\fR .PP Set the label process type for the container processes. .SS \fBShmSize=\fR .PP Size of /dev/shm. .PP This is equivalent to the Podman \fB--shm-size\fR option and generally has the form \fBnumber[unit]\fR .SS \fBStopSignal=\fR .PP Signal to stop a container. Default is \fBSIGTERM\fP\&. .PP This is equivalent to the Podman \fB--stop-signal\fR option .SS \fBStopTimeout=\fR .PP Seconds to wait before forcibly stopping the container. .PP Note, this value should be lower than the actual systemd unit timeout to make sure the podman rm command is not killed by systemd. .PP This is equivalent to the Podman \fB--stop-timeout\fR option .SS \fBSubGIDMap=\fR .PP Run the container in a new user namespace using the map with name in the /etc/subgid file. Equivalent to the Podman \fB--subgidname\fR option. .SS \fBSubUIDMap=\fR .PP Run the container in a new user namespace using the map with name in the /etc/subuid file. Equivalent to the Podman \fB--subuidname\fR option. .SS \fBSysctl=\fR .PP Configures namespaced kernel parameters for the container. The format is \fBSysctl=name=value\fR\&. .PP This is a space separated list of kernel parameters. This key can be listed multiple times. .PP For example: .EX Sysctl=net.ipv6.conf.all.disable_ipv6=1 net.ipv6.conf.all.use_tempaddr=1 .EE .SS \fBTimezone=\fR (if unset uses system-configured default) .PP The timezone to run the container in. .SS \fBTmpfs=\fR .PP Mount a tmpfs in the container. This is equivalent to the Podman \fB--tmpfs\fR option, and generally has the form \fBCONTAINER-DIR[:OPTIONS]\fR\&. .PP This key can be listed multiple times. .SS \fBUIDMap=\fR .PP Run the container in a new user namespace using the supplied UID mapping. Equivalent to the Podman \fB--uidmap\fR option. .PP This key can be listed multiple times. .SS \fBUlimit=\fR .PP Ulimit options. Sets the ulimits values inside of the container. .PP This key can be listed multiple times. .SS \fBUnmask=\fR .PP Specify the paths to unmask separated by a colon. unmask=ALL or /path/1:/path/2, or shell expanded paths (/proc/*): .PP If set to \fBALL\fR, Podman will unmask all the paths that are masked or made read-only by default. .PP The default masked paths are /proc/acpi, /proc/kcore, /proc/keys, /proc/latency_stats, /proc/sched_debug, /proc/scsi, /proc/timer_list, /proc/timer_stats, /sys/firmware, and /sys/fs/selinux. .PP The default paths that are read-only are /proc/asound, /proc/bus, /proc/fs, /proc/irq, /proc/sys, /proc/sysrq-trigger, /sys/fs/cgroup. .SS \fBUser=\fR .PP The (numeric) UID to run as inside the container. This does not need to match the UID on the host, which can be modified with \fBUserNS\fR, but if that is not specified, this UID is also used on the host. .SS \fBUserNS=\fR .PP Set the user namespace mode for the container. This is equivalent to the Podman \fB--userns\fR option and generally has the form \fBMODE[:OPTIONS,...]\fR\&. .SS \fBVolume=\fR .PP Mount a volume in the container. This is equivalent to the Podman \fB--volume\fR option, and generally has the form \fB[[SOURCE-VOLUME|HOST-DIR:]CONTAINER-DIR[:OPTIONS]]\fR\&. .PP If \fBSOURCE-VOLUME\fR starts with \fB\&.\fR, Quadlet resolves the path relative to the location of the unit file. .PP As a special case, if \fBSOURCE-VOLUME\fR ends with \fB\&.volume\fR, a Podman named volume called \fBsystemd-$name\fR is used as the source, and the generated systemd service contains a dependency on the \fB$name-volume.service\fR\&. Such a volume can be automatically be lazily created by using a \fB$name.volume\fR Quadlet file. .PP This key can be listed multiple times. .SS \fBWorkingDir=\fR .PP Working directory inside the container. .PP The default working directory for running binaries within a container is the root directory (/). The image developer can set a different default with the WORKDIR instruction. This option overrides the working directory by using the -w option. .SH Pod units [Pod] .PP Pod units are named with a \fB\&.pod\fR extension and contain a \fB[Pod]\fR section describing the pod that is created and run as a service. The resulting service file contains a line like \fBExecStartPre=podman pod create …\fR, and most of the keys in this section control the command-line options passed to Podman. .PP By default, the Podman pod has the same name as the unit, but with a \fBsystemd-\fR prefix, i.e. a \fB$name.pod\fR file creates a \fB$name-pod.service\fR unit and a \fBsystemd-$name\fR Podman pod. The \fBPodName\fR option allows for overriding this default name with a user-provided one. .PP Valid options for \fB[Pod]\fR are listed below: .TS allbox; l l l l . \fB\fB[Pod] options\fP\fP \fB\fBpodman container create equivalent\fP\fP ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf GlobalArgs=--log-level=debug --log-level=debug Network=host --network host NetworkAlias=name --network-alias name PodmanArgs=--cpus=2 --cpus=2 PodName=name --name=name PublishPort=50-59 --publish 50-59 Volume=/source:/dest --volume /source:/dest .TE .PP Supported keys in the \fB[Pod]\fR section are: .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBpod\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBNetwork=\fR .PP Specify a custom network for the pod. This has the same format as the \fB--network\fR option to \fBpodman pod create\fR\&. For example, use \fBhost\fR to use the host network in the pod, or \fBnone\fR to not set up networking in the pod. .PP As a special case, if the \fBname\fR of the network ends with \fB\&.network\fR, Quadlet will look for the corresponding \fB\&.network\fR Quadlet unit. If found, Quadlet will use the name of the Network set in the Unit, otherwise, \fBsystemd-$name\fR is used. The generated systemd service contains a dependency on the service unit generated for that \fB\&.network\fR unit, or on \fB$name-network.service\fR if the \fB\&.network\fR unit is not found .PP This key can be listed multiple times. .SS \fBNetworkAlias=\fR .PP Add a network-scoped alias for the pod. This has the same format as the \fB--network-alias\fR option to \fBpodman pod create\fR\&. Aliases can be used to group containers together in DNS resolution: for example, setting \fBNetworkAlias=web\fR on multiple containers will make a DNS query for \fBweb\fR resolve to all the containers with that alias. .PP This key can be listed multiple times. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman pod create\fR command in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBPodName=\fR .PP The (optional) name of the Podman pod. If this is not specified, the default value of \fBsystemd-%N\fR is used, which is the same as the service name but with a \fBsystemd-\fR prefix to avoid conflicts with user-managed containers. .PP Please note that pods and containers cannot have the same name. So, if PodName is set, it must not conflict with any container. .SS \fBPublishPort=\fR .PP Exposes a port, or a range of ports (e.g. \fB50-59\fR), from the pod to the host. Equivalent to the Podman \fB--publish\fR option. The format is similar to the Podman options, which is of the form \fBip:hostPort:containerPort\fR, \fBip::containerPort\fR, \fBhostPort:containerPort\fR or \fBcontainerPort\fR, where the number of host and container ports must be the same (in the case of a range). .PP If the IP is set to 0.0.0.0 or not set at all, the port is bound on all IPv4 addresses on the host; use [::] for IPv6. .PP Note that not listing a host port means that Podman automatically selects one, and it may be different for each invocation of service. This makes that a less useful option. The allocated port can be found with the \fBpodman port\fR command. .PP When using \fBhost\fR networking via \fBNetwork=host\fR, the \fBPublishPort=\fR option cannot be used. .PP This key can be listed multiple times. .SS \fBVolume=\fR .PP Mount a volume in the pod. This is equivalent to the Podman \fB--volume\fR option, and generally has the form \fB[[SOURCE-VOLUME|HOST-DIR:]CONTAINER-DIR[:OPTIONS]]\fR\&. .PP If \fBSOURCE-VOLUME\fR starts with \fB\&.\fR, Quadlet resolves the path relative to the location of the unit file. .PP As a special case, if \fBSOURCE-VOLUME\fR ends with \fB\&.volume\fR, Quadlet will look for the corresponding \fB\&.volume\fR Quadlet unit. If found, Quadlet will use the name of the Volume set in the Unit, otherwise, \fBsystemd-$name\fR is used. The generated systemd service contains a dependency on the service unit generated for that \fB\&.volume\fR unit, or on \fB$name-volume.service\fR if the \fB\&.volume\fR unit is not found .PP This key can be listed multiple times. .SH Kube units [Kube] .PP Kube units are named with a \fB\&.kube\fR extension and contain a \fB[Kube]\fR section describing how \fBpodman kube play\fR runs as a service. The resulting service file contains a line like \fBExecStart=podman kube play … file.yml\fR, and most of the keys in this section control the command-line options passed to Podman. However, some options also affect the details of how systemd is set up to run and interact with the container. .PP There is only one required key, \fBYaml\fR, which defines the path to the Kubernetes YAML file. .PP Valid options for \fB[Kube]\fR are listed below: .TS allbox; l l l l . \fB\fB[Kube] options\fP\fP \fB\fBpodman kube play equivalent\fP\fP AutoUpdate=registry T{ --annotation "io.containers.autoupdate=registry" T} ConfigMap=/tmp/config.map --config-map /tmp/config.map ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf ExitCodePropagation=how T{ How to propagate container error status T} GlobalArgs=--log-level=debug --log-level=debug KubeDownForce=true --force (for \fBpodman kube down\fR) LogDriver=journald --log-driver journald Network=host --net host PodmanArgs=--annotation=key=value --annotation=key=value PublishPort=59-60 --publish=59-60 SetWorkingDirectory=yaml Set \fBWorkingDirectory\fR of unit file to location of the YAML file UserNS=keep-id:uid=200,gid=210 T{ --userns keep-id:uid=200,gid=210 T} Yaml=/tmp/kube.yaml T{ podman kube play /tmp/kube.yaml T} .TE .PP Supported keys in the \fB[Kube]\fR section are: .SS \fBAutoUpdate=\fR .PP Indicates whether containers will be auto-updated (podman-auto-update(1)). AutoUpdate can be specified multiple times. The following values are supported: .RS .IP \(bu 2 \fBregistry\fR: Requires a fully-qualified image reference (e.g., quay.io/podman/stable:latest) to be used to create the container. This enforcement is necessary to know which images to actually check and pull. If an image ID was used, Podman does not know which image to check/pull anymore. .IP \(bu 2 \fBlocal\fR: Tells Podman to compare the image a container is using to the image with its raw name in local storage. If an image is updated locally, Podman simply restarts the systemd unit executing the Kubernetes Quadlet. .IP \(bu 2 \fBname/(local|registry)\fR: Tells Podman to perform the \fBlocal\fR or \fBregistry\fR autoupdate on the specified container name. .RE .SS \fBConfigMap=\fR .PP Pass the Kubernetes ConfigMap YAML path to \fBpodman kube play\fR via the \fB--configmap\fR argument. Unlike the \fBconfigmap\fR argument, the value may contain only one path but it may be absolute or relative to the location of the unit file. .PP This key may be used multiple times .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBExitCodePropagation=\fR .PP Control how the main PID of the systemd service should exit. The following values are supported: - \fBall\fR: exit non-zero if all containers have failed (i.e., exited non-zero) - \fBany\fR: exit non-zero if any container has failed - \fBnone\fR: exit zero and ignore failed containers .PP The current default value is \fBnone\fR\&. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBkube\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBKubeDownForce=\fR .PP Remove all resources, including volumes, when calling \fBpodman kube down\fR\&. Equivalent to the Podman \fB--force\fR option. .SS \fBLogDriver=\fR .PP Set the log-driver Podman uses when running the container. Equivalent to the Podman \fB--log-driver\fR option. .SS \fBNetwork=\fR .PP Specify a custom network for the container. This has the same format as the \fB--network\fR option to \fBpodman kube play\fR\&. For example, use \fBhost\fR to use the host network in the container, or \fBnone\fR to not set up networking in the container. .PP As a special case, if the \fBname\fR of the network ends with \fB\&.network\fR, a Podman network called \fBsystemd-$name\fR is used, and the generated systemd service contains a dependency on the \fB$name-network.service\fR\&. Such a network can be automatically created by using a \fB$name.network\fR Quadlet file. .PP This key can be listed multiple times. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman kube play\fR command in the generated file (right before the path to the yaml file in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBPublishPort=\fR .PP Exposes a port, or a range of ports (e.g. \fB50-59\fR), from the container to the host. Equivalent to the \fBpodman kube play\fR\&'s \fB--publish\fR option. The format is similar to the Podman options, which is of the form \fBip:hostPort:containerPort\fR, \fBip::containerPort\fR, \fBhostPort:containerPort\fR or \fBcontainerPort\fR, where the number of host and container ports must be the same (in the case of a range). .PP If the IP is set to 0.0.0.0 or not set at all, the port is bound on all IPv4 addresses on the host; use [::] for IPv6. .PP The list of published ports specified in the unit file is merged with the list of ports specified in the Kubernetes YAML file. If the same container port and protocol is specified in both, the entry from the unit file takes precedence .PP This key can be listed multiple times. .SS \fBSetWorkingDirectory=\fR .PP Set the \fBWorkingDirectory\fR field of the \fBService\fR group of the Systemd service unit file. Used to allow \fBpodman kube play\fR to correctly resolve relative paths. Supported values are \fByaml\fR and \fBunit\fR to set the working directory to that of the YAML or Quadlet Unit file respectively. .PP Alternatively, users can explicitly set the \fBWorkingDirectory\fR field of the \fBService\fR group in the \fB\&.kube\fR file. Please note that if the \fBWorkingDirectory\fR field of the \fBService\fR group is set, Quadlet will not set it even if \fBSetWorkingDirectory\fR is set .SS \fBUserNS=\fR .PP Set the user namespace mode for the container. This is equivalent to the Podman \fB--userns\fR option and generally has the form \fBMODE[:OPTIONS,...]\fR\&. .SS \fBYaml=\fR .PP The path, absolute or relative to the location of the unit file, to the Kubernetes YAML file to use. .SH Network units [Network] .PP Network files are named with a \fB\&.network\fR extension and contain a section \fB[Network]\fR describing the named Podman network. The generated service is a one-time command that ensures that the network exists on the host, creating it if needed. .PP By default, the Podman network has the same name as the unit, but with a \fBsystemd-\fR prefix, i.e. for a network file named \fB$NAME.network\fR, the generated Podman network is called \fBsystemd-$NAME\fR, and the generated service file is \fB$NAME-network.service\fR\&. The \fBNetworkName\fR option allows for overriding this default name with a user-provided one. .PP Please note that stopping the corresponding service will not remove the podman network. In addition, updating an existing network is not supported. In order to update the network parameters you will first need to manually remove the podman network and then restart the service. .PP Using network units allows containers to depend on networks being automatically pre-created. This is particularly interesting when using special options to control network creation, as Podman otherwise creates networks with the default options. .PP Valid options for \fB[Network]\fR are listed below: .TS allbox; l l l l . \fB\fB[Network] options\fP\fP \fB\fBpodman network create equivalent\fP\fP ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf DisableDNS=true --disable-dns DNS=192.168.55.1 --dns=192.168.55.1 Driver=bridge --driver bridge Gateway=192.168.55.3 --gateway 192.168.55.3 GlobalArgs=--log-level=debug --log-level=debug Internal=true --internal IPAMDriver=dhcp --ipam-driver dhcp IPRange=192.168.55.128/25 --ip-range 192.168.55.128/25 IPv6=true --ipv6 Label="XYZ" --label "XYZ" NetworkName=foo podman network create foo Options=isolate=true --opt isolate=true PodmanArgs=--dns=192.168.55.1 --dns=192.168.55.1 Subnet=192.5.0.0/16 --subnet 192.5.0.0/16 .TE .PP Supported keys in \fB[Network]\fR section are: .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBDisableDNS=\fR (defaults to \fBfalse\fR) .PP If enabled, disables the DNS plugin for this network. .PP This is equivalent to the Podman \fB--disable-dns\fR option .SS \fBDNS=\fR .PP Set network-scoped DNS resolver/nameserver for containers in this network. .PP This key can be listed multiple times. .SS \fBDriver=\fR (defaults to \fBbridge\fR) .PP Driver to manage the network. Currently \fBbridge\fR, \fBmacvlan\fR and \fBipvlan\fR are supported. .PP This is equivalent to the Podman \fB--driver\fR option .SS \fBGateway=\fR .PP Define a gateway for the subnet. If you want to provide a gateway address, you must also provide a subnet option. .PP This is equivalent to the Podman \fB--gateway\fR option .PP This key can be listed multiple times. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBnetwork\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBInternal=\fR (defaults to \fBfalse\fR) .PP Restrict external access of this network. .PP This is equivalent to the Podman \fB--internal\fR option .SS \fBIPAMDriver=\fR .PP Set the ipam driver (IP Address Management Driver) for the network. Currently \fBhost-local\fR, \fBdhcp\fR and \fBnone\fR are supported. .PP This is equivalent to the Podman \fB--ipam-driver\fR option .SS \fBIPRange=\fR .PP Allocate container IP from a range. The range must be a either a complete subnet in CIDR notation or be in the \fB-\fR syntax which allows for a more flexible range compared to the CIDR subnet. The ip-range option must be used with a subnet option. .PP This is equivalent to the Podman \fB--ip-range\fR option .PP This key can be listed multiple times. .SS \fBIPv6=\fR .PP Enable IPv6 (Dual Stack) networking. .PP This is equivalent to the Podman \fB--ipv6\fR option .SS \fBLabel=\fR .PP Set one or more OCI labels on the network. The format is a list of \fBkey=value\fR items, similar to \fBEnvironment\fR\&. .PP This key can be listed multiple times. .SS \fBNetworkName=\fR .PP The (optional) name of the Podman network. If this is not specified, the default value of \fBsystemd-%N\fR is used, which is the same as the unit name but with a \fBsystemd-\fR prefix to avoid conflicts with user-managed networks. .SS \fBOptions=\fR .PP Set driver specific options. .PP This is equivalent to the Podman \fB--opt\fR option .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman network create\fR command in the generated file (right before the name of the network in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBSubnet=\fR .PP The subnet in CIDR notation. .PP This is equivalent to the Podman \fB--subnet\fR option .PP This key can be listed multiple times. .SH Volume units [Volume] .PP Volume files are named with a \fB\&.volume\fR extension and contain a section \fB[Volume]\fR describing the named Podman volume. The generated service is a one-time command that ensures that the volume exists on the host, creating it if needed. .PP By default, the Podman volume has the same name as the unit, but with a \fBsystemd-\fR prefix, i.e. for a volume file named \fB$NAME.volume\fR, the generated Podman volume is called \fBsystemd-$NAME\fR, and the generated service file is \fB$NAME-volume.service\fR\&. The \fBVolumeName\fR option allows for overriding this default name with a user-provided one. .PP Using volume units allows containers to depend on volumes being automatically pre-created. This is particularly interesting when using special options to control volume creation, as Podman otherwise creates volumes with the default options. .PP Valid options for \fB[Volume]\fR are listed below: .TS allbox; l l l l . \fB\fB[Volume] options\fP\fP \fB\fBpodman volume create equivalent\fP\fP ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf Copy=true --opt copy Device=tmpfs --opt device=tmpfs Driver=image --driver=image GlobalArgs=--log-level=debug --log-level=debug Group=192 --opt group=192 Image=quay.io/centos/centos:latest T{ --opt image=quay.io/centos/centos:latest T} Label="foo=bar" --label "foo=bar" Options=XYZ --opt "o=XYZ" PodmanArgs=--driver=image --driver=image Type=type Filesystem type of Device User=123 --opt uid=123 VolumeName=foo podman volume create foo .TE .PP Supported keys in \fB[Volume]\fR section are: .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBCopy=\fR (default to \fBtrue\fR) .PP If enabled, the content of the image located at the mountpoint of the volume is copied into the volume on the first run. .SS \fBDevice=\fR .PP The path of a device which is mounted for the volume. .SS \fBDriver=\fR .PP Specify the volume driver name. When set to \fBimage\fR, the \fBImage\fR key must also be set. .PP This is equivalent to the Podman \fB--driver\fR option. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBvolume\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBGroup=\fR .PP The host (numeric) GID, or group name to use as the group for the volume .SS \fBImage=\fR .PP Specifies the image the volume is based on when \fBDriver\fR is set to the \fBimage\fR\&. It is recommended to use a fully qualified image name rather than a short name, both for performance and robustness reasons. .PP The format of the name is the same as when passed to \fBpodman pull\fR\&. So, it supports using \fB:tag\fR or digests to guarantee the specific image version. .PP As a special case, if the \fBname\fR of the image ends with \fB\&.image\fR, Quadlet will use the image pulled by the corresponding \fB\&.image\fR file, and the generated systemd service contains a dependency on the \fB$name-image.service\fR\&. Note that the corresponding \fB\&.image\fR file must exist. .SS \fBLabel=\fR .PP Set one or more OCI labels on the volume. The format is a list of \fBkey=value\fR items, similar to \fBEnvironment\fR\&. .PP This key can be listed multiple times. .SS \fBOptions=\fR .PP The mount options to use for a filesystem as used by the \fBmount(8)\fP command \fB-o\fR option. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman volume create\fR command in the generated file (right before the name of the volume in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBType=\fR .PP The filesystem type of \fBDevice\fR as used by the \fBmount(8)\fP commands \fB-t\fR option. .SS \fBUser=\fR .PP The host (numeric) UID, or user name to use as the owner for the volume .SS \fBVolumeName=\fR .PP The (optional) name of the Podman volume. If this is not specified, the default value of \fBsystemd-%N\fR is used, which is the same as the unit name but with a \fBsystemd-\fR prefix to avoid conflicts with user-managed volumes. .SH Build units [Build] .PP Build files are named with a \fB\&.build\fR extension and contain a section \fB[Build]\fR describing the image build command. The generated service is a one-time command that ensures that the image is built on the host from a supplied Containerfile and context directory. Subsequent (re-)starts of the generated built service will usually finish quickly, as image layer caching will skip unchanged build steps. .PP A minimal \fB\&.build\fR unit needs at least the \fBImageTag=\fR key, and either of \fBFile=\fR or \fBSetWorkingDirectory=\fR keys. .PP Using build units allows containers and volumes to depend on images being built locally. This can be interesting for creating container images not available on container registries, or for local testing and development. .PP Valid options for \fB[Build]\fR are listed below: .TS allbox; l l l l . \fB\fB[Build] options\fP\fP \fB\fBpodman build equivalent\fP\fP Annotation=annotation=value --annotation=annotation=value Arch=aarch64 --arch=aarch64 AuthFile=/etc/registry/auth\&.json --authfile=/etc/registry/auth\&.json ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf DNS=192.168.55.1 --dns=192.168.55.1 DNSOption=ndots:1 --dns-option=ndots:1 DNSSearch=foo.com --dns-search=foo.com Environment=foo=bar --env foo=bar File=/path/to/Containerfile --file=/path/to/Containerfile ForceRM=false --force-rm=false GlobalArgs=--log-level=debug --log-level=debug GroupAdd=keep-groups --group-add=keep-groups ImageTag=localhost/imagename --tag=localhost/imagename Label=label --label=label Network=host --network=host PodmanArgs=--add-host foobar --add-host foobar Pull=never --pull=never Secret=secret --secret=id=mysecret,src=path SetWorkingDirectory=unit Set \fBWorkingDirectory\fR of systemd unit file Target=my-app --target=my-app TLSVerify=false --tls-verify=false Variant=arm/v7 --variant=arm/v7 Volume=/source:/dest --volume /source:/dest .TE .SS \fBAnnotation=\fR .PP Add an image \fIannotation\fP (e.g. annotation=\fIvalue\fP) to the image metadata. Can be used multiple times. .PP This is equivalant to the \fB--annotation\fR option of \fBpodman build\fR\&. .SS \fBArch=\fR .PP Override the architecture, defaults to hosts', of the image to be built. .PP This is equivalent to the \fB--arch\fR option of \fBpodman build\fR\&. .SS \fBAuthFile=\fR .PP Path of the authentication file. .PP This is equivalent to the \fB--authfile\fR option of \fBpodman build\fR\&. .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBDNS=\fR .PP Set network-scoped DNS resolver/nameserver for the build container. .PP This key can be listed multiple times. .PP This is equivalent to the \fB--dns\fR option of \fBpodman build\fR\&. .SS \fBDNSOption=\fR .PP Set custom DNS options. .PP This key can be listed multiple times. .PP This is equivalent to the \fB--dns-option\fR option of \fBpodman build\fR\&. .SS \fBDNSSearch=\fR .PP Set custom DNS search domains. Use \fBDNSSearch=.\fP to remove the search domain. .PP This key can be listed multiple times. .PP This is equivalent to the \fB--dns-search\fR option of \fBpodman build\fR\&. .SS \fBEnvironment=\fR .PP Add a value (e.g. env=\fIvalue\fP) to the built image. This uses the same format as services in systemd \[la]https://www.freedesktop.org/software/systemd/man/systemd.exec.html#Environment=\[ra] and can be listed multiple times. .SS \fBFile=\fR .PP Specifies a Containerfile which contains instructions for building the image. A URL starting with \fBhttp(s)://\fR allows you to specify a remote Containerfile to be downloaded. Note that for a given relative path to a Containerfile, or when using a \fBhttp(s)://\fR URL, you also must set \fBSetWorkingDirectory=\fR in order for \fBpodman build\fR to find a valid context directory for the resources specified in the Containerfile. .PP Note that setting a \fBFile=\fR field is mandatory for a \fB\&.build\fR file, unless \fBSetWorkingDirectory\fR (or a \fBWorkingDirectory\fR in the \fBService\fR group) has also been set. .PP This is equivalent to the \fB--file\fR option of \fBpodman build\fR\&. .SS \fBForceRM=\fR .PP Always remove intermediate containers after a build, even if the build fails (default true). .PP This is equivalent to the \fB--force-rm\fR option of \fBpodman build\fR\&. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBbuild\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBGroupAdd=\fR .PP Assign additional groups to the primary user running within the container process. Also supports the \fBkeep-groups\fR special flag. .PP This is equivalent to the \fB--group-add\fR option of \fBpodman build\fR\&. .SS \fBImageTag=\fR .PP Specifies the name which is assigned to the resulting image if the build process completes successfully. .PP This is equivalent to the \fB--tag\fR option of \fBpodman build\fR\&. .SS \fBLabel=\fR .PP Add an image \fIlabel\fP (e.g. label=\fIvalue\fP) to the image metadata. Can be used multiple times. .PP This is equivalent to the \fB--label\fR option of \fBpodman build\fR\&. .SS \fBNetwork=\fR .PP Sets the configuration for network namespaces when handling RUN instructions. This has the same format as the \fB--network\fR option to \fBpodman build\fR\&. For example, use \fBhost\fR to use the host network, or \fBnone\fR to not set up networking. .PP As a special case, if the \fBname\fR of the network ends with \fB\&.network\fR, Quadlet will look for the corresponding \fB\&.network\fR Quadlet unit. If found, Quadlet will use the name of the Network set in the Unit, otherwise, \fBsystemd-$name\fR is used. The generated systemd service contains a dependency on the service unit generated for that \fB\&.network\fR unit, or on \fB$name-network.service\fR if the \fB\&.network\fR unit is not found. .PP This key can be listed multiple times. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman build\fR command in the generated file (right before the image name in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBPull=\fR .PP Set the image pull policy. .PP This is equivalent to the \fB--pull\fR option of \fBpodman build\fR\&. .SS \fBSecret=\fR .PP Pass secret information used in Containerfile build stages in a safe way. .PP This is equivalent to the \fB--secret\fR option of \fBpodman build\fR and generally has the form \fBsecret[,opt=opt ...]\fR\&. .SS \fBSetWorkingDirectory=\fR .PP Provide context (a working directory) to \fBpodman build\fR\&. Supported values are a path, a URL, or the special keys \fBfile\fR or \fBunit\fR to set the context directory to the parent directory of the file from the \fBFile=\fR key or to that of the Quadlet \fB\&.build\fR unit file, respectively. This allows Quadlet to resolve relative paths. .PP When using one of the special keys (\fBfile\fR or \fBunit\fR), the \fBWorkingDirectory\fR field of the \fBService\fR group of the Systemd service unit will also be set to accordingly. Alternatively, users can explicitly set the \fBWorkingDirectory\fR field of the \fBService\fR group in the \fB\&.build\fR file. Please note that if the \fBWorkingDirectory\fR field of the \fBService\fR group is set by the user, Quadlet will not overwrite it even if \fBSetWorkingDirectory\fR is set to \fBfile\fR or \fBunit\fR\&. .PP By providing a URL to \fBSetWorkingDirectory=\fR you can instruct \fBpodman build\fR to clone a Git repository or download an archive file extracted to a temporary location by \fBpodman build\fR as build context. Note that in this case, the \fBWorkingDirectory\fR of the Systemd service unit is left untouched by Quadlet. .PP Note that providing context directory is mandatory for a \fB\&.build\fR file, unless a \fBFile=\fR key has also been provided. .SS \fBTarget=\fR .PP Set the target build stage to build. Commands in the Containerfile after the target stage are skipped. .PP This is equivalent to the \fB--target\fR option of \fBpodman build\fR\&. .SS \fBTLSVerify=\fR .PP Require HTTPS and verification of certificates when contacting registries. .PP This is equivalent to the \fB--tls-verify\fR option of \fBpodman build\fR\&. .SS \fBVariant=\fR .PP Override the default architecture variant of the container image to be built. .PP This is equivalent to the \fB--variant\fR option of \fBpodman build\fR\&. .SS \fBVolume=\fR .PP Mount a volume to containers when executing RUN instructions during the build. This is equivalent to the \fB--volume\fR option of \fBpodman build\fR, and generally has the form \fB[[SOURCE-VOLUME|HOST-DIR:]CONTAINER-DIR[:OPTIONS]]\fR\&. .PP If \fBSOURCE-VOLUME\fR starts with \fB\&.\fR, Quadlet resolves the path relative to the location of the unit file. .PP As a special case, if \fBSOURCE-VOLUME\fR ends with \fB\&.volume\fR, Quadlet will look for the corresponding \fB\&.volume\fR Quadlet unit. If found, Quadlet will use the name of the Volume set in the Unit, otherwise, \fBsystemd-$name\fR is used. The generated systemd service contains a dependency on the service unit generated for that \fB\&.volume\fR unit, or on \fB$name-volume.service\fR if the \fB\&.volume\fR unit is not found .PP This key can be listed multiple times. .SH Image units [Image] .PP Image files are named with a \fB\&.image\fR extension and contain a section \fB[Image]\fR describing the container image pull command. The generated service is a one-time command that ensures that the image exists on the host, pulling it if needed. .PP Using image units allows containers and volumes to depend on images being automatically pulled. This is particularly interesting when using special options to control image pulls. .PP Note: The generated service have a dependency on \fBnetwork-online.target\fR assuring the network is reachable if an image needs to be pulled. If the image service needs to run without available network (e.g. early in boot), the requirement can be overriden simply by adding an empty \fBAfter=\fR in the unit file. This will unset all previously set After's. .PP Valid options for \fB[Image]\fR are listed below: .TS allbox; l l l l . \fB\fB[Image] options\fP\fP \fB\fBpodman image pull equivalent\fP\fP AllTags=true --all-tags Arch=aarch64 --arch=aarch64 AuthFile=/etc/registry/auth\&.json --authfile=/etc/registry/auth\&.json CertDir=/etc/registry/certs --cert-dir=/etc/registry/certs ContainersConfModule=/etc/nvd\&.conf --module=/etc/nvd\&.conf Creds=myname:mypassword --creds=myname:mypassword DecryptionKey=/etc/registry\&.key --decryption-key=/etc/registry\&.key GlobalArgs=--log-level=debug --log-level=debug Image=quay\&.io/centos/centos:latest T{ podman image pull quay.io/centos/centos:latest T} ImageTag=quay\&.io/centos/centos:latest Use this name when resolving \fB\&.image\fR references OS=windows --os=windows PodmanArgs=--os=linux --os=linux TLSVerify=false --tls-verify=false Variant=arm/v7 --variant=arm/v7 .TE .SS \fBAllTags=\fR .PP All tagged images in the repository are pulled. .PP This is equivalent to the Podman \fB--all-tags\fR option. .SS \fBArch=\fR .PP Override the architecture, defaults to hosts, of the image to be pulled. .PP This is equivalent to the Podman \fB--arch\fR option. .SS \fBAuthFile=\fR .PP Path of the authentication file. .PP This is equivalent to the Podman \fB--authfile\fR option. .SS \fBCertDir=\fR .PP Use certificates at path (*.crt, *.cert, *.key) to connect to the registry. .PP This is equivalent to the Podman \fB--cert-dir\fR option. .SS \fBContainersConfModule=\fR .PP Load the specified containers.conf(5) module. Equivalent to the Podman \fB--module\fR option. .PP This key can be listed multiple times. .SS \fBCreds=\fR .PP The \fB[username[:password]]\fR to use to authenticate with the registry, if required. .PP This is equivalent to the Podman \fB--creds\fR option. .SS \fBDecryptionKey=\fR .PP The \fB[key[:passphrase]]\fR to be used for decryption of images. .PP This is equivalent to the Podman \fB--decryption-key\fR option. .SS \fBGlobalArgs=\fR .PP This key contains a list of arguments passed directly between \fBpodman\fR and \fBimage\fR in the generated file. It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBImage=\fR .PP The image to pull. It is recommended to use a fully qualified image name rather than a short name, both for performance and robustness reasons. .PP The format of the name is the same as when passed to \fBpodman pull\fR\&. So, it supports using \fB:tag\fR or digests to guarantee the specific image version. .SS \fBImageTag=\fR .PP Actual FQIN of the referenced \fBImage\fR\&. Only meaningful when source is a file or directory archive. .PP For example, an image saved into a \fBdocker-archive\fR with the following Podman command: .PP \fBpodman image save --format docker-archive --output /tmp/archive-file.tar quay.io/podman/stable:latest\fR .PP requires setting - \fBImage=docker-archive:/tmp/archive-file.tar\fR - \fBImageTag=quay.io/podman/stable:latest\fR .SS \fBOS=\fR .PP Override the OS, defaults to hosts, of the image to be pulled. .PP This is equivalent to the Podman \fB--os\fR option. .SS \fBPodmanArgs=\fR .PP This key contains a list of arguments passed directly to the end of the \fBpodman image pull\fR command in the generated file (right before the image name in the command line). It can be used to access Podman features otherwise unsupported by the generator. Since the generator is unaware of what unexpected interactions can be caused by these arguments, it is not recommended to use this option. .PP The format of this is a space separated list of arguments, which can optionally be individually escaped to allow inclusion of whitespace and other control characters. .PP This key can be listed multiple times. .SS \fBTLSVerify=\fR .PP Require HTTPS and verification of certificates when contacting registries. .PP This is equivalent to the Podman \fB--tls-verify\fR option. .SS \fBVariant=\fR .PP Override the default architecture variant of the container image. .PP This is equivalent to the Podman \fB--variant\fR option. .SH EXAMPLES .PP Example \fBtest.container\fR: .EX [Unit] Description=A minimal container [Container] # Use the centos image Image=quay.io/centos/centos:latest # Use volume and network defined below Volume=test.volume:/data Network=test.network # In the container we just run sleep Exec=sleep 60 [Service] # Restart service when sleep finishes Restart=always # Extend Timeout to allow time to pull the image TimeoutStartSec=900 # ExecStartPre flag and other systemd commands can go here, see systemd.unit(5) man page. ExecStartPre=/usr/share/mincontainer/setup.sh [Install] # Start by default on boot WantedBy=multi-user.target default.target .EE .PP Example \fBtest.kube\fR: .EX [Unit] Description=A kubernetes yaml based service Before=local-fs.target [Kube] Yaml=/opt/k8s/deployment.yml [Install] # Start by default on boot WantedBy=multi-user.target default.target .EE .PP Example for locally built image to be used in a container: .PP \fBtest.build\fR .EX [Build] # Tag the image to be built ImageTag=localhost/imagename # Set the working directory to the path of the unit file, # expecting to find a Containerfile/Dockerfile # + other files needed to build the image SetWorkingDirectory=unit .EE .PP \fBtest.container\fR .EX [Container] Image=test.build .EE .PP Example \fBtest.volume\fR: .EX [Volume] User=root Group=root Label=org.test.Key=value .EE .PP Example \fBtest.network\fR: .EX [Network] Subnet=172.16.0.0/24 Gateway=172.16.0.1 IPRange=172.16.0.0/28 Label=org.test.Key=value .EE .PP Example for Container in a Pod: .PP \fBtest.pod\fR .EX [Pod] PodName=test .EE .PP \fBcentos.container\fR .EX [Container] Image=quay.io/centos/centos:latest Exec=sh -c "sleep inf" Pod=test.pod .EE .PP Example \fBs3fs.volume\fR: .PP For further details, please see the s3fs-fuse project. Remember to read the FAQ .PP .RS .PP NOTE: Enabling the cache massively speeds up access and write times on static files/objects. .PP However, \fBuse_cache\fR is UNBOUNDED! .PP Be careful, it will fill up with any files accessed on the s3 bucket through the file system. .RE .PP Please remember to set \fBS3_BUCKET\fR, \fBPATH\fR, \fBAWS_REGION\fR\&. \fBCACHE_DIRECTORY\fR should be set up by systemd .EX [Service] CacheDirectory=s3fs ExecStartPre=/usr/local/bin/aws s3api put-object --bucket ${S3_BUCKET} --key ${PATH}/ [Volume] Device=${S3_BUCKET}:/${PATH} Type=fuse.s3fs VolumeName=s3fs-volume Options=iam_role,endpoint=${AWS_REGION},use_xattr,listobjectsv2,del_cache,use_cache=${CACHE_DIRECTORY} # `iam_role` assumes inside EC2, if not, Use `profile=` instead .EE .SH SEE ALSO .PP \fBsystemd.unit(5)\fP, \fBsystemd.service(5)\fP, \fBpodman-run(1)\fP, \fBpodman-network-create(1)\fP, \fBpodman-auto-update(1)\fP \fB[systemd.unit(5)]\fP