From e7655ebe4532999c439e8a53e16e800b5d2f3ecf Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Thu, 1 Oct 2026 21:52:01 +0100 Subject: [PATCH] Use quadlets to configure podman services --- cookbooks/imagery/recipes/tiler.rb | 1 + cookbooks/podman/resources/service.rb | 32 ++++---- cookbooks/systemd/resources/container.rb | 75 +++++++++++++++++++ .../systemd/templates/default/container.erb | 36 +++++++++ 4 files changed, 126 insertions(+), 18 deletions(-) create mode 100644 cookbooks/systemd/resources/container.rb create mode 100644 cookbooks/systemd/templates/default/container.erb diff --git a/cookbooks/imagery/recipes/tiler.rb b/cookbooks/imagery/recipes/tiler.rb index 7733bd638..ee242c4cd 100644 --- a/cookbooks/imagery/recipes/tiler.rb +++ b/cookbooks/imagery/recipes/tiler.rb @@ -49,6 +49,7 @@ podman_service "titiler" do :TITILER_API_ROOT_PATH => "/api/v1/titiler", :MOSAIC_CONCURRENCY => "8", :FORWARDED_ALLOW_IPS => "*" # https://docs.gunicorn.org/en/latest/settings.html#forwarded-allow-ips + pids_limit(-1) command "gunicorn -k uvicorn.workers.UvicornWorker titiler.application.main:app --bind unix:/sockets/titiler.sock --workers #{[node.cpu_cores / 2, 2].max} --preload --timeout 180" end diff --git a/cookbooks/podman/resources/service.rb b/cookbooks/podman/resources/service.rb index 43e34164f..09e37367a 100644 --- a/cookbooks/podman/resources/service.rb +++ b/cookbooks/podman/resources/service.rb @@ -27,34 +27,30 @@ property :image, String, :required => true property :ports, Hash, :default => {} property :environment, Hash, :default => {} property :volumes, Hash, :default => {} -property :command, String, :default => "" +property :pids_limit, Integer +property :command, String action :create do systemd_service new_resource.service do + action :delete + end + + systemd_container new_resource.service do description new_resource.description - type "notify" - notify_access "all" - environment "PODMAN_SYSTEMD_UNIT" => "%n" - exec_start_pre "/bin/rm --force %t/%n.ctr-id" - exec_start "/usr/bin/podman run --cidfile=%t/%n.ctr-id --cgroups=no-conmon " \ - "--userns=auto --label=io.containers.autoupdate=registry " \ - "--pids-limit=-1 #{publish_options} #{environment_options} " \ - "#{volume_options} --rm --sdnotify=conmon --detach --replace " \ - "--name=%N #{new_resource.image} #{new_resource.command}" - exec_stop "/usr/bin/podman stop --ignore --time=10 --cidfile=%t/%n.ctr-id" - exec_stop_post "/usr/bin/podman rm --force --ignore --cidfile=%t/%n.ctr-id" + image new_resource.image + command new_resource.command + ports new_resource.ports + environment new_resource.environment + volumes new_resource.volumes + pids_limit new_resource.pids_limit timeout_start_sec 180 - timeout_stop_sec 70 restart "on-failure" end # No action :start here to avoid a start and then immediate :restart, due to subscribe, on first run - # FIXME: Ubuntu 22.04 podman/crun bug workaround "retries" service new_resource.service do - action :enable - subscribes :restart, "systemd_service[#{new_resource.service}]", :immediately - retries 4 # Workaround https://github.com/containers/podman/issues/9752 - retry_delay 5 + action :nothing + subscribes :restart, "systemd_container[#{new_resource.service}]", :immediately end # Ensure the service is started if not running, replies on status of service resource diff --git a/cookbooks/systemd/resources/container.rb b/cookbooks/systemd/resources/container.rb new file mode 100644 index 000000000..cb76ab30b --- /dev/null +++ b/cookbooks/systemd/resources/container.rb @@ -0,0 +1,75 @@ +# +# Cookbook:: systemd +# Resource:: systemd_container +# +# Copyright:: 2026, OpenStreetMap Foundation +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# https://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# + +unified_mode true + +default_action :create + +property :container, String, :name_property => true +property :description, String +property :image, String +property :command, String +property :ports, Hash, :default => {} +property :environment, Hash, :default => {} +property :volumes, Hash, :default => {} +property :pids_limit, Integer +property :timeout_start_sec, Integer +property :restart, String, + :is => %w[on-success on-failure on-abnormal on-watchdog on-abort always] + +action :create do + container_variables = new_resource.to_hash + + template config_name do + cookbook "systemd" + source "container.erb" + owner "root" + group "root" + mode "644" + variables container_variables + end + + execute "systemctl-reload" do + action :nothing + command "systemctl daemon-reload" + user "root" + group "root" + subscribes :run, "template[#{config_name}]" + end +end + +action :delete do + file config_name do + action :delete + end + + execute "systemctl-reload" do + action :nothing + command "systemctl daemon-reload" + user "root" + group "root" + subscribes :run, "file[#{config_name}]" + end +end + +action_class do + def config_name + "/etc/containers/systemd/#{new_resource.container}.container" + end +end diff --git a/cookbooks/systemd/templates/default/container.erb b/cookbooks/systemd/templates/default/container.erb new file mode 100644 index 000000000..82312eb6d --- /dev/null +++ b/cookbooks/systemd/templates/default/container.erb @@ -0,0 +1,36 @@ +[Unit] +<% if @description -%> +Description=<%= @description %> +<% end -%> + +[Container] +<% if @image -%> +Image=<%= @image %> +<% end -%> +<% if @command -%> +Exec=<%= @command %> +<% end -%> +<% @ports.each do |host, guest| -%> +PublishPort=127.0.0.1:<%= host %>:<%= guest %> +<% end -%> +<% @environment.each do |name, value| -%> +Environment=<%= name %>=<%= value %> +<% end -%> +<% @volumes.each do |source, path| -%> +Volume=<%= source %>:<%= path %> +<% end -%> +<% if @pids_limit -%> +PidsLimit=<%= @pids_limit %> +<% end -%> +AutoUpdate=registry + +[Service] +<% if @restart -%> +Restart=<%= @restart %> +<% end -%> +<% if @timeout_start_sec -%> +TimeoutStartSec=<%= @timeout_start_sec %> +<% end -%> + +[Install] +WantedBy=default.target -- 2.47.3