Repository navigation
Add Podman local runtime support - #1136
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2801a129af
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
- reject remote Podman connections\n- search all healthy runtimes for orphan cleanup\n- strip ANSI escapes from followed logs
There was a problem hiding this comment.
💡 Codex Review
kitaru/src/kitaru/cli/local_runtime.py
Lines 234 to 235 in 835dd40
When state.json is missing and both engines are healthy, _get_container_runner() selects Docker first and this call inspects only that engine. A stopped Podman deployment or retained volume is therefore missed, after which login writes new Docker state and secrets and presents an empty database while the Podman data remains orphaned. Fresh evidence after the earlier feedback is that only stop_local_runtime() now loops over _get_available_container_runners(); this startup path still passes the single preferred runner here. Inspect all healthy engines for labeled resources before writing new ownership state.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Addressed in d0460ac: first startup now inspects every installed healthy runtime for unowned labeled resources before writing ownership state, while an explicitly injected runner remains bounded to that runner. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d0460ac7b9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7aac70320b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| project: Literal["kitaru-local"] = "kitaru-local" | ||
| server_image: str | ||
| port: int = Field(default=DEFAULT_LOCAL_PORT, ge=1, le=65535) | ||
| runtime: ContainerRuntime = "docker" |
There was a problem hiding this comment.
Persist the Podman connection that owns the deployment
When a deployment is created on local Podman connection A and the user later selects another valid local connection B, the state records only runtime="podman", so start_local_runtime, stop_local_runtime, and get_local_logs silently operate on B. In particular, logout --volumes can successfully run compose down where no project exists and then delete the state and secrets, leaving the actual containers and database volume orphaned on A. This is a supported configuration change—Podman documents system connection default as setting a named destination as the default Podman service—so persist and verify the connection identity before operating on or deleting deployment state.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
persist and verify the connection identity before operating on or deleting deployment state.
This is the third review round on how Kitaru identifies the Podman service behind a deployment, so I am stopping before adding another local guard. The state currently records only runtime="podman"; fixing this properly requires choosing a durable identity and a migration rule for existing state.
The options are: persist the selected connection name and normalized URI, then explicitly select and verify it for every command; persist an identity but only reject when the active connection changes; or declare connection switching unsupported and fail when more than one local connection makes ownership ambiguous. I lean toward the first option because it keeps commands attached to the service that created the data. We still need to decide how legacy state without a stored connection should behave before implementing it.
Summary
Testing
just checkuv run pytest tests/cli -q(616 passed)podman-compose1.6.0: interactive create, logs without ANSI escapes, reuse, and volume deletion.dockerexecutable ahead of a healthy Podman machine: fresh interactive login selected Podman, persisted it, and reused the deployment.podman-compose: local Podman Machine validation, healthy create, ANSI-free followed JSONL logs, and volume deletion.Reviewer Notes
Reproduction
podman compose versionsucceeds.PATH.kitaru login --local --port 19080 --no-browser.kitaru status,kitaru local logs --tail 5, and the login command again. The second login should reportdeployment: reused.kitaru logout, log in again to confirm the database is retained, then clean up withkitaru logout --volumes.To exercise the native provider explicitly, set
PODMAN_COMPOSE_PROVIDERto the path returned bycommand -v podman-composebefore step 3.The main review points are the persisted
runtimefield and state-less orphan cleanup. Legacy state defaults to Docker, new deployments keep using the runtime that created their data, and recovery without state checks every installed healthy runtime for labeled resources.