Commit graph

42 commits

Author SHA1 Message Date
Jens Petersen
274bdf9053 findutils missing docs 2022-08-09 14:27:08 +08:00
c74e5c7926 Make locate(1) opt-in by default
Currently, the entry point of a Toolbox container runs updatedb(8) on
start-up, which can be very I/O intensive. This might be a hindrance
when troubleshooting performance problems on a host, or when
re-creating containers somewhat more frequently.

Users can install the mlocate RPM and restart their containers to
enable locate(1).

https://github.com/containers/toolbox/pull/938
2021-12-01 16:57:19 +01:00
86be929465 Remove misleading and redundant CMD
There's no need to specify a CMD in a Toolbox image because it's
specified by 'toolbox create', through 'podman create', when creating a
container.

A CMD was specified [1] because the Fedora Container Guidelines
requires it [2]. The idea behind the guidelines is that the right
thing should happen when one runs:
  $ podman run <image>

However, that only makes sense for images targeting single service
containers. Toolbox containers and images are different - they are not
meant to be used like that to run a single one-off service.

Conceptually, 'running' a Toolbox container is expected to provide the
user with a reasonable interactive command line experience. Arguably,
that means offering something like /bin/bash, not /bin/sh.

Also, note that when the CMD was introduced [1], Toolbox containers
were actually created, through 'podman create', with /bin/sh as their
entry points. So, it did make some sense. However, things have changed
since then [3]. The entry point is now 'toolbox init-container'. It's
not possible to mention it in the Toolbox image because the
/usr/bin/toolbox binary isn't present in the image, and it's not meant
to be present.

Therefore, today, /bin/sh is simply not the right fit for a Toolbox
image's CMD. A better option would be /bin/bash.

Note that the fedora base images have their CMD set to /bin/bash, which
is inherited by the fedora-toolbox images.

So, there are two options. Either repeat the same CMD in the
fedora-toolbox images and satisfy the guidelines, or take some
liberties and let the CMD be inherited from the fedora base images.

This commit takes the latter option. People tend to use the
fedora-toolbox images as the starting point for other custom Toolbox
images, sometimes for other operating system distributions. It's
better to keep them minimal to avoid implying extra requirements. In
this case, the CMD is an abstract concept, and the actual entry point
is 'toolbox init-container' as specified by 'toolbox create'.
Specifying /bin/bash might discourage people from creating custom
images that are only meant to have /bin/zsh.

Also, note that the current CMD was actually '/bin/sh -c /bin/sh', not
/bin/sh. Unless a CMD is specified as an array of command line
arguments, it's passed as a single argument to '/bin/sh -c' [4]. So,
this:
  CMD foo bar

... is the same as:
  CMD [ "/bin/sh", "-c", "foo bar" ]

[1] Toolbox commit 5cc2678a3677af44
    5cc2678a36

[2] https://docs.fedoraproject.org/en-US/containers/guidelines/creation/

[3] Toolbox commit 8b84b5e4604921fa
    https://github.com/containers/toolbox/pull/160

[4] https://docs.docker.com/engine/reference/builder/#cmd

https://github.com/containers/toolbox/issues/885
2021-12-01 15:21:56 +01:00
a69d81176c extra-packages: Avoid losing mount(8) by accident
The util-linux package was added to ensure the presence of the mount(8)
command. Currently the package is already pulled in by various
dependencies. Therefore, it doesn't increase the size of the image, but
serves as a safeguard against any inadvertent changes.

Note that starting from Fedora 35 onwards, the fedora base images no
longer have mount(8), which increases the importance of this change.

https://github.com/containers/toolbox/issues/929
2021-11-25 19:50:42 +01:00
f7288e6863 Ensure that coreutils-single is replaced by coreutils-full
It's true that the fedora base images no longer come with
coreutils-single, but they used to, and the ubi base images still do.
Therefore, it's worth being extra defensive about this.

It's better to make the build system execute one extra redundant
command than expose users to a bug because of a change that snuck in
unnoticed.

This reverts commit a2171d8742.

https://github.com/containers/toolbox/pull/931
2021-11-25 19:50:04 +01:00
Jens Petersen
c637c4bfa9 fedora:35+ no longer includes acl, openssl, systemd (#1988886)
and this breaks the koji buildContainer build somehow
2021-08-12 12:01:58 +08:00
Oliver Gutierrez
f131a12ec5
Added iproute package 2021-07-09 10:06:48 +01:00
Oliver Gutierrez
030ad6d052
Reverted changes in README.md 2021-06-29 16:46:38 +01:00
Oliver Gutierrez
692c49780c
Reverted renaming of Dockerfile 2021-06-29 16:03:09 +01:00
Oliver Gutierrez
7105bdf49e
Renamed Dockerfile to Containerfile and updated README.md 2021-06-29 16:00:33 +01:00
085c05199b Add bc and update README.md 2021-06-29 16:19:55 +02:00
Otto Urpelainen
8ad99234bd Include the nano default editor
Since Fedora 33, `nano` is the default editor[0]. It needs to be
included in the fedora-toolbox image to have the standard Fedora
experience inside the container.

https://fedoraproject.org/wiki/Changes/UseNanoByDefault).
2021-03-10 11:31:22 +01:00
Jens Petersen
8d796028ba rawhide is now Fedora 35 2021-02-19 12:07:10 +08:00
Ondřej Míchal
d863edf9d7 Simplify image name
Currently the images are named as "f<version>/fedora-toolbox". This is
troublesome for new users of toolbox (even those with some background to
containers) because everywhere the image is advertised or talked about
as "fedora-toolbox". This is taken care of by Toolbox CLI but has no
effect on Podman itself (or any other tool capable of working with OCI
images).

Another pain point is in the Fedora registry[0] all "fedora-toolbox"
images get a different entry for every version of Fedora. There is no
single place for all "fedora-toolbox" images.

With this change I propose to only use "fedora-toolbox" as the name of
the container and make use of VERSION to distinguish between versions of
Fedora. Currently when you go to the Fedora registry and find an entry
for "fedora-toolbox" you'll see all previous images. I believe that with
this change that "feature" will be lost. But I personally find that
"feature" to be rather confusing because what usually a user wants the
latest version of a container (I partially base this statement on the
fact that most images are versioned this way; e.g. Ubuntu on Docker
Hub[1]).

[0] https://registry.fedoraproject.org/
[1] https://hub.docker.com/_/ubuntu
2020-12-02 18:10:47 +01:00
f6e830047e Give access to Avahi to resolve the .local mDNS domain
The nss-mdns plugin for the GNU Name Service Switch (or NSS)
functionality of the GNU C Library is necessary to resolve the .local
mDNS domain. The plugin talks to the Avahi daemon running on the host
to resolve the names.

https://github.com/containers/toolbox/issues/209
2020-11-15 23:26:54 +01:00
0304688fd8 Make locate(1) work inside toolbox containers
This reverts commit bd035973c9.

https://github.com/containers/toolbox/issues/391
2020-11-15 23:25:56 +01:00
efa6be73c3 extra-packages: Allow X11 clients to run as root
If an X11 client is started inside a 'su -' session, then xauth(1)
needs to be present so that pam_xauth.so can add a new XAUTHORITY
environment variable to the 'su -' session.

https://github.com/containers/toolbox/pull/572
2020-10-30 19:45:38 +01:00
e7d30ac5c1 Bump version to 34 for master 2020-08-21 16:26:51 +02:00
d8b3e6baac extra-packages: Add gvfs-client
The gvfs-client package is necessary for GIO-based processes inside
toolbox containers to use the GVfs backend and volume monitor daemons,
and it comes preinstalled on Fedora Silverblue and Workstation.

https://github.com/containers/toolbox/pull/466
2020-06-15 19:43:24 +02:00
f064121de5 Revert "no need to explicitly list krb5-libs"
Currently, krb5-libs is pulled in by various other packages that are
already part of the fedora-toolbox OCI image. Unless someone is keeping
a close eye on the contents of the image, a change in the package
dependencies or the contents of the base fedora OCI image can cause
krb5-libs to go missing from the fedora-toolbox image.

This would be undesirable because toolbox(1) relies on the presence
of the /etc/krb5.conf file and the /etc/krb5.conf.d directory to set
up Kerberos inside a toolbox container, and those are provided by the
krb5-libs package.

Therefore, explicitly listing krb5-libs prevents us from accidentally
losing Kerberos integration in toolbox containers, and doesn't cost us
anything because it's already part of the image anyway.

This reverts commit f552b51ec2.
2020-06-15 19:15:35 +02:00
Jens Petersen
f552b51ec2 no need to explicitly list krb5-libs 2020-05-26 11:49:20 +08:00
Jens Petersen
bd035973c9 drop mlocate: https://github.com/containers/toolbox/issues/391 2020-04-11 10:59:09 +08:00
Jens Petersen
c4524abdf2 try removing uninstalled packages from missing-docs (error 143)
atomic_reactor.util - Package chkconfig available, but not installed.
atomic_reactor.util - No match for argument: chkconfig
atomic_reactor.util - Package dbus-daemon available, but not installed.
atomic_reactor.util - No match for argument: dbus-daemon
atomic_reactor.util - Package rpm-plugin-systemd-inhibit available, but not installed.
atomic_reactor.util - No match for argument: rpm-plugin-systemd-inhibit
:
:
atomic_reactor.util - DEBUG - Running scriptlet: gawk-5.0.1-7.fc32.x86_64  38/38
atomic_reactor.util - DEBUG - Removing intermediate container a533251cf472
atomic_reactor.util - ERROR - {'errorDetail': {'code': 143, 'message': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}, 'error': "The command '/bin/sh -c dnf -y reinstall $(<missing-docs)' returned a non-zero code: 143"}
2020-02-28 10:17:46 +08:00
Jens Petersen
7b8140e725 bump version to 33 for master 2020-02-21 22:49:31 +08:00
fccc0ad0cf Update the label for tagging to reflect the project's new home
https://github.com/containers/toolbox/pull/293
2019-10-10 16:02:22 +02:00
7a9383999e Install only flatpak-spawn, not the rest of flatpak-xdg-utils
https://github.com/debarshiray/toolbox/issues/147
2019-09-24 21:05:43 +02:00
74cfade587 Avoid losing useradd(8) by accident
The shadow-utils package was added to the base toolbox images to ensure
the presence of the useradd(8) command. Currently the package is
already pulled in by various dependencies. Therefore, it doesn't
increase the size of the base image, but serves as a safeguard against
any inadvertent changes.
2019-09-24 20:10:54 +02:00
Jens Petersen
a2171d8742 base image no longer uses coreutils-single
https://github.com/fedora-cloud/docker-brew-fedora/issues/58
2019-09-02 17:50:22 +08:00
Jens Petersen
384327a6cf Bump version to 32 for master 2019-09-02 16:25:56 +08:00
Jens Petersen
1bc06dcae7 drop PackageKit-command-not-found
(it connects to the host)
2019-07-11 10:44:24 +00:00
6b3e14fdcb Add label for tagging, not tied to the fedora-toolbox name
Currently the toolbox script identifies toolbox images and containers
by checking whether the com.redhat.component label matches
"fedora-toolbox". However, as per the Fedora Container Guidelines [1],
the com.redhat.com label should match the Red Hat Bugzilla component
name where bugs against the image should be reported. This means that
images derived from the base fedora-toolbox image would likely end up
overwriting it.

One option would've been to mandate that all toolbox images have the
"fedora-toolbox-" prefix in their names. However, it's better to avoid
putting limitations on how images can be named. The "fedora" name
wouldn't anyway work for images based on other distributions, and not
all images are going to use the Red Hat bugzilla for tracking bugs.

It's better to use a tag that's uniquely associated with the toolbox
project, and isn't tied to a particular distribution or bug tracker.

[1] https://fedoraproject.org/wiki/Container:Guidelines
2019-04-15 18:00:43 +02:00
a427cd46a7 Synchronize with upstream 2019-03-21 18:20:30 +01:00
c4ab8c7873 Reduce the size by removing temporary files created by DNF
For a locally built squashed fedora-toolbox:29 image [1], the size
reported by 'podman images' goes from 630 MB to 425 MB.

[1] Using: buildah bud --squash ...
2019-03-21 18:19:56 +01:00
ca845d52ec extra-packages: Add krb5-libs
The krb5-libs package was added to the base toolbox images to ensure
the presence of the /etc/krb5.conf.d directory with the correct
permissions. Currently, the package is already pulled in by various
dependencies. Therefore, it doesn't increase the size of the base
image, but serves as a safeguard against any inadvertent changes.

https://github.com/debarshiray/toolbox/pull/74
2019-03-21 18:19:10 +01:00
54f5f60e49 Restore documentation removed from the base Fedora images
https://github.com/debarshiray/toolbox/pull/55
2019-03-21 18:18:06 +01:00
ec141174f3 extra-packages: Add flatpak-xdg-utils 2019-02-25 14:56:35 +01:00
47193f42c7 Synchronize with upstream 2019-02-25 14:56:35 +01:00
62506d9f58 Bump version to 31 for master 2019-02-25 14:56:35 +01:00
ce76b5229f Dockerfile: Simplify the package installation 2018-09-26 13:29:47 +02:00
88351f1ebe Bump version to 30 for master 2018-09-25 13:35:55 +02:00
b2678e8ee5 Add the rest of the files 2018-09-25 11:38:52 +02:00
af37d2fd50 Added the README 2018-09-24 19:32:43 +00:00