Merge pull request #19230 from rhatdan/quadlet
Add support for ShmSize to quadlet
This commit is contained in:
commit
2a559dc1a1
|
|
@ -158,6 +158,7 @@ Valid options for `[Container]` are listed below:
|
|||
| SecurityLabelLevel=s0:c1,c2 | --security-opt label=level:s0:c1,c2 |
|
||||
| SecurityLabelNested=true | --security-opt label=nested |
|
||||
| SecurityLabelType=spc_t | --security-opt label=type:spc_t |
|
||||
| ShmSize=100m | --shm-size=100m |
|
||||
| Sysctl=name=value | --sysctl=name=value |
|
||||
| Timezone=local | --tz local |
|
||||
| Tmpfs=/work | --tmpfs /work |
|
||||
|
|
@ -473,6 +474,12 @@ Set the label process type for the container processes.
|
|||
Use a Podman secret in the container either as a file or an environment variable.
|
||||
This is equivalent to the Podman `--secret` option and generally has the form `secret[,opt=opt ...]`
|
||||
|
||||
### `ShmSize=`
|
||||
|
||||
Size of /dev/shm.
|
||||
|
||||
This is equivalent to the Podman `--shm-size` option and generally has the form `number[unit]`
|
||||
|
||||
### `Sysctl=`
|
||||
|
||||
Configures namespaced kernel parameters for the container. The format is `Sysctl=name=value`.
|
||||
|
|
|
|||
|
|
@ -55,6 +55,7 @@ const (
|
|||
KeyEnvironmentFile = "EnvironmentFile"
|
||||
KeyEnvironmentHost = "EnvironmentHost"
|
||||
KeyExec = "Exec"
|
||||
KeyExitCodePropagation = "ExitCodePropagation"
|
||||
KeyExposeHostPort = "ExposeHostPort"
|
||||
KeyGroup = "Group"
|
||||
KeyHealthCmd = "HealthCmd"
|
||||
|
|
@ -69,10 +70,9 @@ const (
|
|||
KeyHealthStartupTimeout = "HealthStartupTimeout"
|
||||
KeyHealthTimeout = "HealthTimeout"
|
||||
KeyHostName = "HostName"
|
||||
KeyImage = "Image"
|
||||
KeyIP = "IP"
|
||||
KeyIP6 = "IP6"
|
||||
KeyExitCodePropagation = "ExitCodePropagation"
|
||||
KeyImage = "Image"
|
||||
KeyLabel = "Label"
|
||||
KeyLogDriver = "LogDriver"
|
||||
KeyMask = "Mask"
|
||||
|
|
@ -102,13 +102,14 @@ const (
|
|||
KeyRootfs = "Rootfs"
|
||||
KeyRunInit = "RunInit"
|
||||
KeySeccompProfile = "SeccompProfile"
|
||||
KeySecret = "Secret"
|
||||
KeySecurityLabelDisable = "SecurityLabelDisable"
|
||||
KeySecurityLabelFileType = "SecurityLabelFileType"
|
||||
KeySecurityLabelLevel = "SecurityLabelLevel"
|
||||
KeySecurityLabelNested = "SecurityLabelNested"
|
||||
KeySecurityLabelType = "SecurityLabelType"
|
||||
KeySecret = "Secret"
|
||||
KeySetWorkingDirectory = "SetWorkingDirectory"
|
||||
KeyShmSize = "ShmSize"
|
||||
KeySysctl = "Sysctl"
|
||||
KeyTimezone = "Timezone"
|
||||
KeyTmpfs = "Tmpfs"
|
||||
|
|
@ -179,6 +180,7 @@ var (
|
|||
KeySecurityLabelLevel: true,
|
||||
KeySecurityLabelNested: true,
|
||||
KeySecurityLabelType: true,
|
||||
KeyShmSize: true,
|
||||
KeySysctl: true,
|
||||
KeyTimezone: true,
|
||||
KeyTmpfs: true,
|
||||
|
|
@ -493,6 +495,11 @@ func ConvertContainer(container *parser.UnitFile, names map[string]string, isUse
|
|||
podman.addf("--cap-add=%s", strings.ToLower(caps))
|
||||
}
|
||||
|
||||
shmSize, hasShmSize := container.Lookup(ContainerGroup, KeyShmSize)
|
||||
if hasShmSize {
|
||||
podman.addf("--shm-size=%s", shmSize)
|
||||
}
|
||||
|
||||
sysctl := container.LookupAllStrv(ContainerGroup, KeySysctl)
|
||||
for _, sysctlItem := range sysctl {
|
||||
podman.addf("--sysctl=%s", sysctlItem)
|
||||
|
|
|
|||
|
|
@ -0,0 +1,5 @@
|
|||
## assert-podman-args "--shm-size=5g"
|
||||
|
||||
[Container]
|
||||
Image=localhost/imagename
|
||||
ShmSize=5g
|
||||
|
|
@ -616,6 +616,7 @@ BOGUS=foo
|
|||
Entry("seccomp.container", "seccomp.container", 0, ""),
|
||||
Entry("secrets.container", "secrets.container", 0, ""),
|
||||
Entry("selinux.container", "selinux.container", 0, ""),
|
||||
Entry("shmsize.container", "shmsize.container", 0, ""),
|
||||
Entry("shortname.container", "shortname.container", 0, "Warning: shortname.container specifies the image \"shortname\" which not a fully qualified image name. This is not ideal for performance and security reasons. See the podman-pull manpage discussion of short-name-aliases.conf for details."),
|
||||
Entry("sysctl.container", "sysctl.container", 0, ""),
|
||||
Entry("timezone.container", "timezone.container", 0, ""),
|
||||
|
|
|
|||
Loading…
Reference in New Issue