Skip to content

Add Podman local runtime support - #1136

Merged
strickvl merged 5 commits into
developfrom
feat/support-podman-local-login
Sep 18, 2026
Merged

strickvl merged 5 commits into
developfrom
feat/support-podman-local-login

Conversation

@strickvl

@strickvl strickvl commented Sep 18, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add Docker-first, validated Podman fallback for CLI-managed local deployments.
  • Persist the selected runtime so later commands keep using the same container and volume store.
  • Handle Podman Compose differences without introducing provider-specific classes or capability detection.
  • Update local-install guidance and add regression coverage for runtime selection, startup, status detection, and logs.

Testing

  • just check
  • uv run pytest tests/cli -q (616 passed)
  • Live Podman Desktop E2E with Podman 6.1.2 and Docker Compose 5.1.2: create, health/status, logs, reuse, stop, restart with retained data, and volume deletion.
  • Live Podman Desktop E2E with podman-compose 1.6.0: interactive create, logs without ANSI escapes, reuse, and volume deletion.
  • Live fallback test with an unusable docker executable ahead of a healthy Podman machine: fresh interactive login selected Podman, persisted it, and reused the deployment.
  • Final-head live test with native podman-compose: local Podman Machine validation, healthy create, ANSI-free followed JSONL logs, and volume deletion.

Reviewer Notes

Reproduction

  1. Start a local Podman machine and ensure podman compose version succeeds.
  2. Stop Docker or remove it from PATH.
  3. Run kitaru login --local --port 19080 --no-browser.
  4. Run kitaru status, kitaru local logs --tail 5, and the login command again. The second login should report deployment: reused.
  5. Run kitaru logout, log in again to confirm the database is retained, then clean up with kitaru logout --volumes.

To exercise the native provider explicitly, set PODMAN_COMPOSE_PROVIDER to the path returned by command -v podman-compose before step 3.

The main review points are the persisted runtime field and state-less orphan cleanup. Legacy state defaults to Docker, new deployments keep using the runtime that created their data, and recovery without state checks every installed healthy runtime for labeled resources.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-18T10:04:41.086265Z 7aac703 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@strickvl
strickvl requested a review from schustmi September 18, 2026 09:26

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2801a129af

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/kitaru/cli/local_runtime.py
Comment thread src/kitaru/cli/local_runtime.py
Comment thread src/kitaru/cli/local_runtime.py Outdated
- reject remote Podman connections\n- search all healthy runtimes for orphan cleanup\n- strip ANSI escapes from followed logs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

if state is None:
await _reject_unowned_resources(runner)

P2 Badge Check every runtime before creating new ownership state

When state.json is missing and both engines are healthy, _get_container_runner() selects Docker first and this call inspects only that engine. A stopped Podman deployment or retained volume is therefore missed, after which login writes new Docker state and secrets and presents an empty database while the Podman data remains orphaned. Fresh evidence after the earlier feedback is that only stop_local_runtime() now loops over _get_available_container_runners(); this startup path still passes the single preferred runner here. Inspect all healthy engines for labeled resources before writing new ownership state.

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@strickvl

Copy link
Copy Markdown
Collaborator Author

Inspect all healthy engines for labeled resources before writing new ownership state.

Addressed in d0460ac: first startup now inspects every installed healthy runtime for unowned labeled resources before writing ownership state, while an explicitly injected runner remains bounded to that runner.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d0460ac7b9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/kitaru/cli/local_runtime.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7aac70320b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

project: Literal["kitaru-local"] = "kitaru-local"
server_image: str
port: int = Field(default=DEFAULT_LOCAL_PORT, ge=1, le=65535)
runtime: ContainerRuntime = "docker"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Persist the Podman connection that owns the deployment

When a deployment is created on local Podman connection A and the user later selects another valid local connection B, the state records only runtime="podman", so start_local_runtime, stop_local_runtime, and get_local_logs silently operate on B. In particular, logout --volumes can successfully run compose down where no project exists and then delete the state and secrets, leaving the actual containers and database volume orphaned on A. This is a supported configuration change—Podman documents system connection default as setting a named destination as the default Podman service—so persist and verify the connection identity before operating on or deleting deployment state.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

persist and verify the connection identity before operating on or deleting deployment state.

This is the third review round on how Kitaru identifies the Podman service behind a deployment, so I am stopping before adding another local guard. The state currently records only runtime="podman"; fixing this properly requires choosing a durable identity and a migration rule for existing state.

The options are: persist the selected connection name and normalized URI, then explicitly select and verify it for every command; persist an identity but only reject when the active connection changes; or declare connection switching unsupported and fail when more than one local connection makes ownership ambiguous. I lean toward the first option because it keeps commands attached to the service that created the data. We still need to decide how legacy state without a stored connection should behave before implementing it.

@strickvl
strickvl merged commit 0162b28 into develop Sep 18, 2026
40 checks passed
@strickvl
strickvl deleted the feat/support-podman-local-login branch September 18, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants