Compare commits

...

1 Commits

Author SHA1 Message Date
Briquet 0f0bcff376 [WIP] 🔧(dev) make the dev stack work with rootless podman
Rootless podman maps container UID 0 to the host user and every other
container UID to a subuid that owns nothing in the worktree, so the usual
DOCKER_USER=$(id -u):$(id -g) makes every bind mount effectively
read-only.

Pin the LiveKit rtc section: the browser reaches the server through
podman's published ports on loopback while egress and the agents reach
it over the podman network, and those two have no address in common.
`advertise_internal_ip` keeps the container's own interface address as a
host candidate alongside the node_ip one, so LiveKit offers both and ICE
picks whichever works. Without it egress only ever sees 127.0.0.1, which
is the egress container itself, and its peer connection timeouts

Prerequisite on the host: systemctl --user enable --now podman.socket
2026-09-14 17:58:21 +02:00
4 changed files with 22 additions and 7 deletions
+7 -2
View File
@@ -36,9 +36,14 @@ DB_PORT = 5432
# -- Docker # -- Docker
# Get the current user ID to use for docker run and docker exec commands # Get the current user ID to use for docker run and docker exec commands
ifneq ($(findstring podman,$(DOCKER_HOST)),)
DOCKER_UID = 0
DOCKER_GID = 0
else
DOCKER_UID = $(shell id -u) DOCKER_UID = $(shell id -u)
DOCKER_GID = $(shell id -g) DOCKER_GID = $(shell id -g)
DOCKER_USER = $(DOCKER_UID):$(DOCKER_GID) endif
DOCKER_USER ?= $(DOCKER_UID):$(DOCKER_GID)
COMPOSE = DOCKER_USER=$(DOCKER_USER) docker compose COMPOSE = DOCKER_USER=$(DOCKER_USER) docker compose
COMPOSE_EXEC = $(COMPOSE) exec COMPOSE_EXEC = $(COMPOSE) exec
COMPOSE_EXEC_APP = $(COMPOSE_EXEC) app-dev COMPOSE_EXEC_APP = $(COMPOSE_EXEC) app-dev
@@ -292,7 +297,7 @@ shell: ## connect to database shell
# -- Database # -- Database
dbshell: ## connect to database shell dbshell: ## connect to database shell
docker compose exec app-dev python manage.py dbshell @$(COMPOSE_EXEC_APP) python manage.py dbshell
.PHONY: dbshell .PHONY: dbshell
resetdb: FLUSH_ARGS ?= resetdb: FLUSH_ARGS ?=
+5 -2
View File
@@ -25,8 +25,11 @@ function _set_user() {
return return
fi fi
# USER_ID = USER_ID or `id -u` if USER_ID is not set # USER_ID = USER_ID or the engine-appropriate default if USER_ID is not set.
USER_ID=${USER_ID:-$(id -u)} case "${DOCKER_HOST:-}" in
*podman*) USER_ID=${USER_ID:-0} ;;
*) USER_ID=${USER_ID:-$(id -u)} ;;
esac
echo "🙋(user) ID: ${USER_ID}" echo "🙋(user) ID: ${USER_ID}"
} }
@@ -21,3 +21,10 @@ turn:
- 192.168.0.0/16 - 192.168.0.0/16
- 172.16.0.0/12 - 172.16.0.0/12
rtc:
node_ip: 127.0.0.1
advertise_internal_ip: true
udp_port: 7882
tcp_port: 7881
use_external_ip: false
+3 -3
View File
@@ -4,12 +4,12 @@ USER node
WORKDIR /home/frontend/ WORKDIR /home/frontend/
COPY ./src/frontend/package.json ./package.json COPY --chown=node:node ./src/frontend/package.json ./package.json
COPY ./src/frontend/package-lock.json ./package-lock.json COPY --chown=node:node ./src/frontend/package-lock.json ./package-lock.json
RUN npm ci RUN npm ci
COPY .dockerignore ./.dockerignore COPY --chown=node:node .dockerignore ./.dockerignore
COPY --chown=node:node ./src/frontend/ . COPY --chown=node:node ./src/frontend/ .
### ---- Front-end builder image ---- ### ---- Front-end builder image ----