Since Fedora 33, `nano` is the default editor[0]. It needs to be
included in the fedora-toolbox image to have the standard Fedora
experience inside the container.
https://fedoraproject.org/wiki/Changes/UseNanoByDefault).
Currently the images are named as "f<version>/fedora-toolbox". This is
troublesome for new users of toolbox (even those with some background to
containers) because everywhere the image is advertised or talked about
as "fedora-toolbox". This is taken care of by Toolbox CLI but has no
effect on Podman itself (or any other tool capable of working with OCI
images).
Another pain point is in the Fedora registry[0] all "fedora-toolbox"
images get a different entry for every version of Fedora. There is no
single place for all "fedora-toolbox" images.
With this change I propose to only use "fedora-toolbox" as the name of
the container and make use of VERSION to distinguish between versions of
Fedora. Currently when you go to the Fedora registry and find an entry
for "fedora-toolbox" you'll see all previous images. I believe that with
this change that "feature" will be lost. But I personally find that
"feature" to be rather confusing because what usually a user wants the
latest version of a container (I partially base this statement on the
fact that most images are versioned this way; e.g. Ubuntu on Docker
Hub[1]).
[0] https://registry.fedoraproject.org/
[1] https://hub.docker.com/_/ubuntu
The nss-mdns plugin for the GNU Name Service Switch (or NSS)
functionality of the GNU C Library is necessary to resolve the .local
mDNS domain. The plugin talks to the Avahi daemon running on the host
to resolve the names.
https://github.com/containers/toolbox/issues/209
If an X11 client is started inside a 'su -' session, then xauth(1)
needs to be present so that pam_xauth.so can add a new XAUTHORITY
environment variable to the 'su -' session.
https://github.com/containers/toolbox/pull/572
The gvfs-client package is necessary for GIO-based processes inside
toolbox containers to use the GVfs backend and volume monitor daemons,
and it comes preinstalled on Fedora Silverblue and Workstation.
https://github.com/containers/toolbox/pull/466
Currently, krb5-libs is pulled in by various other packages that are
already part of the fedora-toolbox OCI image. Unless someone is keeping
a close eye on the contents of the image, a change in the package
dependencies or the contents of the base fedora OCI image can cause
krb5-libs to go missing from the fedora-toolbox image.
This would be undesirable because toolbox(1) relies on the presence
of the /etc/krb5.conf file and the /etc/krb5.conf.d directory to set
up Kerberos inside a toolbox container, and those are provided by the
krb5-libs package.
Therefore, explicitly listing krb5-libs prevents us from accidentally
losing Kerberos integration in toolbox containers, and doesn't cost us
anything because it's already part of the image anyway.
This reverts commit f552b51ec2.
atomic_reactor.util - Package chkconfig available, but not installed.
atomic_reactor.util - No match for argument: chkconfig
atomic_reactor.util - Package dbus-daemon available, but not installed.
atomic_reactor.util - No match for argument: dbus-daemon
atomic_reactor.util - Package rpm-plugin-systemd-inhibit available, but not installed.
atomic_reactor.util - No match for argument: rpm-plugin-systemd-inhibit
:
:
atomic_reactor.util - DEBUG - Running scriptlet: gawk-5.0.1-7.fc32.x86_64 38/38
atomic_reactor.util - DEBUG - Removing intermediate container a533251cf472
atomic_reactor.util - ERROR - {'errorDetail': {'code': 143, 'message': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}, 'error': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}
The shadow-utils package was added to the base toolbox images to ensure
the presence of the useradd(8) command. Currently the package is
already pulled in by various dependencies. Therefore, it doesn't
increase the size of the base image, but serves as a safeguard against
any inadvertent changes.
Currently the toolbox script identifies toolbox images and containers
by checking whether the com.redhat.component label matches
"fedora-toolbox". However, as per the Fedora Container Guidelines [1],
the com.redhat.com label should match the Red Hat Bugzilla component
name where bugs against the image should be reported. This means that
images derived from the base fedora-toolbox image would likely end up
overwriting it.
One option would've been to mandate that all toolbox images have the
"fedora-toolbox-" prefix in their names. However, it's better to avoid
putting limitations on how images can be named. The "fedora" name
wouldn't anyway work for images based on other distributions, and not
all images are going to use the Red Hat bugzilla for tracking bugs.
It's better to use a tag that's uniquely associated with the toolbox
project, and isn't tied to a particular distribution or bug tracker.
[1] https://fedoraproject.org/wiki/Container:Guidelines
For a locally built squashed fedora-toolbox:29 image [1], the size
reported by 'podman images' goes from 630 MB to 425 MB.
[1] Using: buildah bud --squash ...
The krb5-libs package was added to the base toolbox images to ensure
the presence of the /etc/krb5.conf.d directory with the correct
permissions. Currently, the package is already pulled in by various
dependencies. Therefore, it doesn't increase the size of the base
image, but serves as a safeguard against any inadvertent changes.
https://github.com/debarshiray/toolbox/pull/74