fix(podman): use Type=notify + service-container so systemd sees pod crashes
The previous Type=oneshot + RemainAfterExit=true pattern made systemd freeze pod units in 'active (exited)' as soon as 'podman play kube' returned, so crash-looping containers were invisible to 'systemctl --user --failed' and Restart=on-failure never fired. For every podman-pod role (immich, fdroid, ntfy, gitea, qfieldcloud, unifi, matrix, uptime_kuma): - switch units to Type=notify + NotifyAccess=all - run 'podman kube play --service-container=true' so the unit's main PID stays alive as long as the pod - use 'podman kube down' for ExecStop - add TimeoutStartSec=180 to cover slow first-boot image pulls Pod manifests: flip every container's restartPolicy from Always to Never. systemd is now the single owner of the restart loop: container exits -> pod dies -> service container dies -> unit fails -> Restart=on-failure restarts everything cleanly. With Always, podman retried internally and hid the failure from systemd. CLAUDE.md updated to document the new canonical template and the 'restartPolicy: Never' requirement.
This commit is contained in:
@@ -0,0 +1,15 @@
|
||||
[Unit]
|
||||
Description=F-Droid Repository Server
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
NotifyAccess=all
|
||||
WorkingDirectory={{ podman_projects_dir | default('/opt/podman') }}/fdroid
|
||||
ExecStart=/usr/bin/podman kube play --replace --service-container=true --network=pasta:--map-host-loopback={{ podman_gw_gateway }} fdroid.yaml
|
||||
ExecStop=/usr/bin/podman kube down fdroid.yaml
|
||||
Restart=on-failure
|
||||
RestartSec=10
|
||||
TimeoutStartSec=180
|
||||
|
||||
[Install]
|
||||
WantedBy=default.target
|
||||
@@ -0,0 +1,53 @@
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Pod
|
||||
metadata:
|
||||
name: fdroid
|
||||
labels:
|
||||
app: fdroid
|
||||
spec:
|
||||
containers:
|
||||
- name: server
|
||||
image: {{ fdroid_image }}:{{ fdroid_version }}
|
||||
ports:
|
||||
- containerPort: 80
|
||||
hostPort: {{ fdroid_port }}
|
||||
env:
|
||||
- name: TZ
|
||||
value: "Europe/Paris"
|
||||
- name: FDROID_REPO_URL
|
||||
value: "{{ fdroid_repo_url }}"
|
||||
- name: FDROID_REPO_NAME
|
||||
value: "{{ fdroid_repo_name }}"
|
||||
- name: FDROID_REPO_DESCRIPTION
|
||||
value: "{{ fdroid_repo_description }}"
|
||||
- name: FDROID_REPO_ICON
|
||||
value: "{{ fdroid_repo_icon }}"
|
||||
- name: FDROID_UPDATE_INTERVAL
|
||||
value: "{{ fdroid_update_interval }}"
|
||||
command: ["bash", "-c"]
|
||||
args: ["apache2ctl -D FOREGROUND & fdroid update -c && while true; do sleep {{ fdroid_update_interval }} && fdroid update; done"]
|
||||
volumeMounts:
|
||||
- name: localtime
|
||||
mountPath: /etc/localtime
|
||||
readOnly: true
|
||||
- name: fdroid-data
|
||||
mountPath: /fdroid
|
||||
- name: fdroid-repo
|
||||
mountPath: /var/www/html/repo
|
||||
readOnly: true
|
||||
restartPolicy: Never
|
||||
|
||||
volumes:
|
||||
- name: localtime
|
||||
hostPath:
|
||||
path: /etc/localtime
|
||||
type: File
|
||||
- name: fdroid-data
|
||||
hostPath:
|
||||
path: {{ fdroid_data_dir }}
|
||||
type: Directory
|
||||
- name: fdroid-repo
|
||||
hostPath:
|
||||
path: {{ fdroid_data_dir }}/repo
|
||||
type: Directory
|
||||
Reference in New Issue
Block a user