Container Storage Library
Go to file
Giuseppe Scrivano 9bf64bb716
archive, rootless: use user.* instead of trusted.*
unprivileged users cannot use the trusted.* xattrs.  Since for
rootless we always mount overlay with userxattr, we can just check if
running in rootless mode and use user.* instead of trusted.*.

Closes: https://github.com/containers/podman/issues/9936

Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
2021-04-06 17:10:24 +02:00
.github Add dependabot.yml configuration file 2021-03-03 11:43:22 +01:00
cmd/containers-storage containers-storage: add --volatile to container create 2021-03-01 21:11:40 +01:00
contrib/cirrus Use an xz library instead of shelling out to xz for decompression 2021-03-22 12:18:25 -04:00
docs Inherit system storage driver in rootless configurations 2021-03-02 10:28:53 -06:00
drivers copy, rootless: skip copying trusted.* xattr 2021-04-06 16:55:18 +02:00
hack Fix problems found by codespell 2020-09-11 10:49:59 -04:00
internal/opts Fix problems found by codespell 2020-09-11 10:49:59 -04:00
pkg archive, rootless: use user.* instead of trusted.* 2021-04-06 17:10:24 +02:00
tests overlay.recreateSymlinks: handle missing "link" files, add a test 2021-03-23 09:45:12 -04:00
types types: check for native overlay support 2021-03-05 09:27:23 +01:00
vagrant Use `bash` binary from env instead of /bin/bash for scripts 2020-08-17 11:23:44 +02:00
vendor Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
.cirrus.yml Cirrus: Do not update/install packages at runtime 2021-01-18 19:35:33 -05:00
.dockerignore
.gitignore Fixes: https://github.com/containers/podman/issues/7790 2020-10-06 11:39:51 +08:00
.golangci.yml Enable all linters and selectively disable them 2020-01-28 16:09:15 +01:00
.mailmap Fix double entry in authors 2016-06-03 12:40:36 +02:00
AUTHORS Inherit system storage driver in rootless configurations 2021-03-02 10:28:53 -06:00
CODE-OF-CONDUCT.md Add Code of Conduct 2020-02-08 18:13:47 -05:00
CONTRIBUTING.md Change cri-o IRC channel to container-projects in CONTRIBUTING.md 2017-10-26 17:02:34 -04:00
LICENSE Update LICENSE date 2015-12-31 13:07:35 +00:00
Makefile Makefile local-test-unit: use -race if it's available 2021-02-23 10:37:50 -05:00
NOTICE Update LICENSE date 2015-12-31 13:07:35 +00:00
README.md make: clean up .PHONY targets list 2018-10-31 19:03:59 +01:00
SECURITY.md Add Security Policy 2020-05-09 18:12:41 -04:00
VERSION Move to v1.28.2-dev 2021-03-24 15:04:50 -04:00
Vagrantfile Vagrantfile: update to Fedora 28 2018-06-29 18:47:10 +02:00
containers.go store: support volatile containers 2021-02-11 10:13:27 +01:00
containers_ffjson.go add digest locks 2019-03-28 09:53:02 +01:00
errors.go Move storageOpts structures into types subdir to shrink bindings. 2021-02-26 05:34:09 -05:00
ffjson_deps.go vendor ffjson deps required during generation 2019-08-05 10:43:25 +02:00
go.mod Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
go.sum Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
idset.go Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
idset_test.go Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
images.go store: support mapped layers deletion 2020-08-05 13:33:43 +02:00
images_ffjson.go Fix ffjson compilation 2020-01-31 10:15:20 +01:00
images_test.go Add names-history support 2019-11-11 10:21:14 +01:00
layers.go layers: support BigData 2021-02-02 11:39:03 +01:00
layers_ffjson.go layers: support BigData 2021-02-02 11:39:03 +01:00
lockfile_compat.go Move lockfiles to their own package 2019-07-02 11:14:04 -04:00
storage.conf Set default to overlay from storage.conf 2021-04-02 05:59:10 -04:00
store.go Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
store_test.go new interface Free for deleting Store object 2020-06-29 13:01:33 -04:00
userns.go Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
userns_test.go Rework autons ID mapping generation. 2021-04-03 13:22:23 -07:00
utils.go Move storageOpts structures into types subdir to shrink bindings. 2021-02-26 05:34:09 -05:00

README.md

storage is a Go library which aims to provide methods for storing filesystem layers, container images, and containers. A containers-storage CLI wrapper is also included for manual and scripting use.

To build the CLI wrapper, use 'make binary'.

Operations which use VMs expect to launch them using 'vagrant', defaulting to using its 'libvirt' provider. The boxes used are also available for the 'virtualbox' provider, and can be selected by setting $VAGRANT_PROVIDER to 'virtualbox' before kicking off the build.

The library manages three types of items: layers, images, and containers.

A layer is a copy-on-write filesystem which is notionally stored as a set of changes relative to its parent layer, if it has one. A given layer can only have one parent, but any layer can be the parent of multiple layers. Layers which are parents of other layers should be treated as read-only.

An image is a reference to a particular layer (its top layer), along with other information which the library can manage for the convenience of its caller. This information typically includes configuration templates for running a binary contained within the image's layers, and may include cryptographic signatures. Multiple images can reference the same layer, as the differences between two images may not be in their layer contents.

A container is a read-write layer which is a child of an image's top layer, along with information which the library can manage for the convenience of its caller. This information typically includes configuration information for running the specific container. Multiple containers can be derived from a single image.

Layers, images, and containers are represented primarily by 32 character hexadecimal IDs, but items of each kind can also have one or more arbitrary names attached to them, which the library will automatically resolve to IDs when they are passed in to API calls which expect IDs.

The library can store what it calls metadata for each of these types of items. This is expected to be a small piece of data, since it is cached in memory and stored along with the library's own bookkeeping information.

Additionally, the library can store one or more of what it calls big data for images and containers. This is a named chunk of larger data, which is only in memory when it is being read from or being written to its own disk file.

Contributing Information about contributing to this project.