bug(examples): podman demo scripts cannot run on macOS (chmod on SPIRE socket fails over virtiofs)
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 45/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- macos, shell
- 領域
- devops, infrastructure
調査の方向性
podman/spire/start-server-oidc.sh、podman/spire/start-agent.sh、podman/README.md から始め、macOS 上の Podman machine を使って失敗を再現し、ホストディレクトリのマウントとソケットの準備完了チェックを追跡します。この変更が Linux のみのサポートを文書化するものなのか、それとも VM 境界を越えて状態と準備完了が機能するようにするものなのかを判断し、サーバー、エージェント、下流のデモコンポーネントが正常に起動することを確認します。
索引モデルが issue の本文から書いたものです。
説明
What happens
Running the Podman SPIFFE token exchange demo on macOS with podman machine, the SPIRE server crashes during startup:
level=info msg="Starting Server APIs" address="[::]:8081" network=tcp
level=error msg="Fatal run error" error="chmod /run/spire/server/private/api.sock: invalid argument"
level=error msg="Server crashed" error="chmod /run/spire/server/private/api.sock: invalid argument"
Every downstream component (OIDC discovery provider, agent, gateway, sandbox) then fails as a consequence, which makes the root cause hard to locate from the symptoms.
Why
podman/spire/start-server-oidc.sh bind-mounts a host directory into the container:
-v "${server_dir}:/run/spire/server:z"
SPIRE creates its API socket in that directory and then chmods it. When SPIRE_STATE_DIR lives on the macOS host, the directory reaches the VM over virtiofs, where chmod on a unix socket returns EINVAL.
podman/spire/start-agent.sh has the same pattern for the Workload API socket:
-v "${agent_dir}:/run/spire/agent:z"
podman/README.md makes no platform statement, so a macOS host reads as a supported configuration.
Workarounds tested
- Podman named volume for
/run/spire/serveravoids thechmodentirely and the server stays up. It has no host path, though, andSPIRE_AGENT_SOCKET_HOST_PATHneeds to be a mountable path because the gateway passes it into sandbox containers. - A path native to the VM (for example under
/var/tmp) works as a bind mount for both server and agent, but the scripts' host-sidemkdir -pandwait_for_socketthen operate on the macOS filesystem rather than the one the containers use, so they create stray directories and the socket wait times out. - Running the scripts entirely inside the Podman machine VM works today, with
SPIRE_STATE_DIRon a VM-native path. This is what we ended up doing.
Suggested fix
Either of:
- Document the demo as requiring a Linux host, which is the cheaper option and sets expectations correctly.
- Place SPIRE state on a filesystem native to the container runtime and wait for readiness via
podman execinside the container rather than polling a host path. That would make the demo work unmodified on macOS.
Environment
- macOS 15 (Darwin 25.6.0), Podman 6.1.1
- Podman machine: Fedora CoreOS 44, kernel 7.0.11 aarch64
- SPIRE images:
ghcr.io/spiffe/spire-server:1.12.4,ghcr.io/spiffe/oidc-discovery-provider:1.12.4
- 主要言語
- Rust
- スター
- 8.7k
- フォーク
- 1.3k
- 平均マージ
- 2日 6時間
- マージ済み PR(30日)
- 297
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
NVIDIA/OpenShell のほかの issue
-
area:docs
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
-
state:triage-needed
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
-
area:cli state:validated
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
-
state:triage-needed
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
-
area:build spike state:review-ready state:stale
難易度 2/5 半日 初心者へのやさしさ 68/100
NVIDIA/OpenShell の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
-
state:needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
zed-industries/zed#64680 · コメント 2 件 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
RustPython/RustPython#8802 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
TheLarkInn/aipm#2390 ·