bug(examples): podman demo scripts cannot run on macOS (chmod on SPIRE socket fails over virtiofs)
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 45/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- macos, shell
- Área
- devops, infrastructure
Línea de trabajo
Comienza con podman/spire/start-server-oidc.sh, podman/spire/start-agent.sh y podman/README.md; reproduce el fallo usando Podman machine en macOS y sigue los montajes de directorios del host y las comprobaciones de disponibilidad del socket. Determina si el cambio documenta que la compatibilidad se limita a Linux o hace que el estado y la disponibilidad funcionen a través del límite de la VM, y verifica que el servidor, el agente y los componentes de demostración posteriores se inicien correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
What happens
Running the Podman SPIFFE token exchange demo on macOS with podman machine, the SPIRE server crashes during startup:
level=info msg="Starting Server APIs" address="[::]:8081" network=tcp
level=error msg="Fatal run error" error="chmod /run/spire/server/private/api.sock: invalid argument"
level=error msg="Server crashed" error="chmod /run/spire/server/private/api.sock: invalid argument"
Every downstream component (OIDC discovery provider, agent, gateway, sandbox) then fails as a consequence, which makes the root cause hard to locate from the symptoms.
Why
podman/spire/start-server-oidc.sh bind-mounts a host directory into the container:
-v "${server_dir}:/run/spire/server:z"
SPIRE creates its API socket in that directory and then chmods it. When SPIRE_STATE_DIR lives on the macOS host, the directory reaches the VM over virtiofs, where chmod on a unix socket returns EINVAL.
podman/spire/start-agent.sh has the same pattern for the Workload API socket:
-v "${agent_dir}:/run/spire/agent:z"
podman/README.md makes no platform statement, so a macOS host reads as a supported configuration.
Workarounds tested
- Podman named volume for
/run/spire/serveravoids thechmodentirely and the server stays up. It has no host path, though, andSPIRE_AGENT_SOCKET_HOST_PATHneeds to be a mountable path because the gateway passes it into sandbox containers. - A path native to the VM (for example under
/var/tmp) works as a bind mount for both server and agent, but the scripts' host-sidemkdir -pandwait_for_socketthen operate on the macOS filesystem rather than the one the containers use, so they create stray directories and the socket wait times out. - Running the scripts entirely inside the Podman machine VM works today, with
SPIRE_STATE_DIRon a VM-native path. This is what we ended up doing.
Suggested fix
Either of:
- Document the demo as requiring a Linux host, which is the cheaper option and sets expectations correctly.
- Place SPIRE state on a filesystem native to the container runtime and wait for readiness via
podman execinside the container rather than polling a host path. That would make the demo work unmodified on macOS.
Environment
- macOS 15 (Darwin 25.6.0), Podman 6.1.1
- Podman machine: Fedora CoreOS 44, kernel 7.0.11 aarch64
- SPIRE images:
ghcr.io/spiffe/spire-server:1.12.4,ghcr.io/spiffe/oidc-discovery-provider:1.12.4
- Lenguaje dominante
- Rust
- Estrellas
- 8.7k
- Forks
- 1.3k
- Merge medio
- 2 d 8 h
- PR fusionados (30 d)
- 271
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de NVIDIA/OpenShell
-
area:docs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
-
state:triage-needed
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
-
area:cli state:validated
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
state:triage-needed
Dificultad 1/5 Menos de una hora Aptitud para principiantes 90/100
-
area:build spike state:review-ready state:stale
Dificultad 2/5 Medio día Aptitud para principiantes 68/100
Todos los issues de NVIDIA/OpenShell
Issues similares
-
Browser (wasm) relay client cannot connect to relays whose URL has a trailing-dot FQDN hostname Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
n0-computer/iroh#4550 ·
-
impl detach for native Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
paritytech/zombienet-sdk#591 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
farion1231/cc-switch#7638 · 1 comentario ·
-
onnx-ir re-exports ModelProto and GraphProto but not NodeProto, AttributeProto and AttributeType Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100