Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ FLOCI_AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
FLOCI_AZURE_RESOURCE_GROUP=floci-local
FLOCI_OCI_ENDPOINT=http://localhost:4599
VITE_MOCK_MODE=false
# Rootless Podman only: uncomment to point docker-compose.yml at Podman's
# Docker-compatible socket instead of the absent /var/run/docker.sock.
# FLOCI_CONTAINER_SOCKET=/run/user/1000/podman/podman.sock
AWS_REGION=us-east-1
AWS_ACCESS_KEY_ID=test
AWS_SECRET_ACCESS_KEY=test
Expand Down
18 changes: 18 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -462,6 +462,24 @@ Start AWS + Azure + GCP + OCI:
docker compose --profile multicloud up
```

#### Podman

The stack runs under Podman with no Docker daemon, but `floci` mounts the host
container socket so it can start throwaway Lambda/Postgres containers. With
rootless Podman there is no `/var/run/docker.sock`, so `podman-compose up` fails
with `Error: statfs /var/run/docker.sock: no such file or directory`. Point the
socket at Podman's Docker-compatible API in a `.env` file:

```bash
echo "FLOCI_CONTAINER_SOCKET=$XDG_RUNTIME_DIR/podman/podman.sock" >> .env
podman-compose up
```

Without the override, Podman never creates the `floci` container at all: the
mount source is missing, so `up` aborts with the `statfs` error above and
`floci-api` then fails its `depends_on` check. No service starts, so there is no
emulator to invoke against.

Convenience targets:

```bash
Expand Down
12 changes: 8 additions & 4 deletions docker-compose.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,10 +48,14 @@ services:
- "4566:4566"
volumes:
# Floci runs Lambda functions in throwaway containers, so it needs the host
# Docker daemon. Without this, invoke fails with "Failed to start Lambda
# container". This grants the emulator control of host Docker — acceptable
# container daemon. Without this, invoke fails with "Failed to start Lambda
# container". This grants the emulator control of the host daemon — acceptable
# for a local dev stack, and the same mount the README's docker run uses.
- /var/run/docker.sock:/var/run/docker.sock
#
# Default is the Docker socket. Podman users, who have no Docker daemon and so
# no /var/run/docker.sock, override it in .env:
# FLOCI_CONTAINER_SOCKET=$XDG_RUNTIME_DIR/podman/podman.sock
- ${FLOCI_CONTAINER_SOCKET:-/var/run/docker.sock}:/var/run/docker.sock

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Rootless socket may be inaccessible If the host user's Podman socket does not permit access by the Floci runtime, which runs as UID 1001, changing the mount source alone will not let Floci connect to it. The stack can start, but Lambda invocations will still fail to start containers. The Podman setup needs to account for socket access as well as its path.

- ./data:/app/data
- ./init/ready.d:/etc/floci/init/ready.d:ro
- ./init/files:/etc/floci/init/files:ro
Expand Down Expand Up @@ -79,7 +83,7 @@ services:
- "4588:4588"
volumes:
# Cloud SQL instances are real Postgres containers; see the note on `floci`.
- /var/run/docker.sock:/var/run/docker.sock
- ${FLOCI_CONTAINER_SOCKET:-/var/run/docker.sock}:/var/run/docker.sock
networks:
- floci_default

Expand Down
Loading