Repository navigation
bug(rpm): allow gateway install on Docker hosts without requiring Podman #2007
Description
Activity
From @drew:
Also need to update it so the gateway doesn't bind on 0.0.0.0
🏗️ build-plan
Implementation Plan
Issue type: fix
Complexity: Medium
Confidence: High — the package path is clear; the bind-address change should be handled separatelySummary
Make the RPM and its user service runtime-neutral so installing
openshell-gatewaynever pulls Podman onto a Docker host. Reuse the existing gateway runtime auto-detection instead of adding an installer-only runtime selector: fresh installs will select a reachable Podman socket when present, otherwise Docker when available.Make installer-triggered service failures visible at the top level. If the gateway cannot start because no runtime is usable, the installer will print service status and recent logs, explain how to install/start Docker or Podman or install and explicitly configure VM, and exit nonzero while leaving the installed packages in place.
Keep the existing RPM
0.0.0.0:17670bind override in this change. PR #1438 established that rootless Podman sandbox callbacks cannot use the loopback-only default; removing the all-interface bind safely requires a separate Podman networking design and live E2E coverage.Scope
openshell.spec: remove the baseRecommends: podmanand gatewayRequires: podman, make package descriptions runtime-neutral, removepodman.socketordering/wants, and preserve first-start config seeding.deploy/rpm/gateway.toml.default: remove the explicitcompute_drivers = ["podman"]pin so the gateway uses existing Kubernetes → Podman → Docker auto-detection; retain the current bind override for Podman compatibility.crates/openshell-server/src/config_file.rs: update the RPM template contract test to require no pinned compute driver while retaining the expected bind address.install.sh: guard Linux service enable/restart/active checks and Homebrew service restart; dump service status and recent journal/Homebrew logs before returning an actionable error. Remediation must distinguish installing/starting Docker or Podman from installing and explicitly configuring the VM driver.tasks/scripts/test-install-sh.sh: cover failed service activation/restart paths, diagnostic collection, actionable runtime remediation text, and nonzero installer results after package installation..github/workflows/rpm-package.yml: verify built RPM metadata has no Podman requirement or recommendation and perform a DNF install transaction with Podman absent.deploy/rpm/QUICKSTART.md,deploy/rpm/CONFIGURATION.md, anddeploy/rpm/TROUBLESHOOTING.md: document runtime-neutral installation, Docker and Podman prerequisites, auto-detection, explicit overrides, upgrade behavior, no-runtime startup failure, and recovery.docs/about/installation.mdx: add a package/runtime prerequisite matrix and explain which installers start services automatically or throughinstall.sh.docs/reference/sandbox-compute-drivers.mdx: document that DEB and Homebrew bundleopenshell-driver-vm, RPM and Snap do not, separate release tarballs are available, and VM is never auto-detected.docs/reference/gateway-config.mdx: align package-managed auto-detection and explicit VM-selection examples with the runtime-neutral RPM defaults.crates/openshell-driver-vm/README.md: replace the stale RPM Podman-pinned description with the new auto-detection behavior and document separate VM artifact installation for RPM hosts.
Implementation Steps
- Remove all RPM dependency and systemd-unit edges that cause DNF or systemd to pull/start Podman.
- Change the seeded RPM configuration to leave compute-driver selection unset so existing runtime auto-detection chooses the available local runtime.
- Make every installer-managed service startup failure dump platform-appropriate diagnostics and return an actionable, package-aware error without rolling back the installed package.
- Update the RPM config contract test, installer shell tests, and artifact-level package dependency/install assertions.
- Update packaged and published documentation with Docker/Podman prerequisites, service-start behavior, the VM inclusion matrix, separate RPM VM installation, no-runtime failure, and recovery paths.
- Run focused tests,
mise run pre-commit, and the existing RPM/Podman validation path as applicable.
Test Plan
- Unit tests: Update
rpm_default_config_parses_and_has_podman_defaultsto assert the template parses, keeps the RPM bind address, and leavescompute_driversunset. Extendtasks/scripts/test-install-sh.shwith mocked Linux and Homebrew service failures that assert diagnostics are emitted, remediation distinguishes available container runtimes from separately installed VM support, and the installer exits nonzero. Run existing compute-driver detection tests. - Integration tests: In the RPM build workflow, inspect
Requires/Recommends, install the generated CLI and gateway RPMs with DNF in the clean Fedora build container, and assert Podman remains uninstalled. - E2E tests: Keep the existing Fedora RPM/Podman release canary as regression coverage. No E2E file change is planned; a Rocky 8 host with Docker CE remains the release-level reproduction target.
Risks & Open Questions
- Removing only the hard requirement is insufficient because DNF installs
Recommendsby default; both Podman dependency edges must be removed. - Existing user-owned
~/.config/openshell/gateway.tomlfiles remain untouched on upgrade, so an existing Podman pin is preserved intentionally. - A direct RPM/DEB package transaction can succeed without a runtime. The higher-level
install.shintentionally exits nonzero if its post-install service verification fails; documentation must make clear that the package remains installed and can be recovered by installing/starting a runtime and restarting the service. - VM packaging differs by installer: DEB installs it under
/usr/libexec/openshell, Homebrew installs it under the formula libexec, RPM and Snap do not include it, and matching standalone release tarballs are published. VM must always be selected explicitly withcompute_drivers = ["vm"]orOPENSHELL_DRIVERS=vm. - On RPM hosts, VM remediation requires installing
openshell-driver-vmunder a configureddriver_diror a conventional path such as~/.local/libexec/openshell,/usr/libexec/openshell, or/usr/local/libexec/openshell; configuration alone is insufficient. - Startup diagnostics must not claim that every failure is caused by a missing runtime. They should show the underlying logs first and present runtime setup as the common remediation for driver-selection failures.
- Binding only to loopback is not included. The previous RPM regression fix documents that this breaks rootless Podman callbacks, so it should be tracked as a separate networking issue unless maintainers request a broader redesign.
- No process identity,
/proc, binary execution, SELinux, or AppArmor behavior changes are expected.
Documentation Impact
Update the RPM quickstart, configuration, and troubleshooting guides; general installation page; gateway configuration reference; compute-driver reference; and VM driver README. The docs will include a package/runtime prerequisite matrix, service-start behavior, VM inclusion and manual-install paths, explicit VM selection, and no-runtime recovery. No Helm or gateway TOML schema changes are expected.
Revision 3 — document runtime prerequisites and VM packaging differences
Revision 2 — add installer startup diagnostics and no-runtime recovery coverage
Revision 1 — initial plan- addedstate:review-readyReady for human reviewReady for human reviewstate:agent-readyApproved for agent implementationApproved for agent implementationstate:in-progressWork is currently in progressWork is currently in progressand removedstate:review-readyReady for human reviewReady for human review
on Jul 3, 2026 Implemented in #2137.
The RPM no longer requires or recommends Podman and its user service no longer orders against
podman.socket. Fresh RPM configs leave compute-driver selection unset so the gateway can select a reachable Podman socket or Docker. Installer-managed startup failures now print service diagnostics, explain that OpenShell remains installed, and provide Docker/Podman or explicitly configured VM recovery steps.The PR also adds RPM metadata/DNF transaction coverage, installer failure tests, the RPM config contract update, and documentation for runtime prerequisites and VM packaging across DEB, RPM, Homebrew, and Snap.
The existing
0.0.0.0:17670RPM bind override remains unchanged because rootless Podman callbacks require it; loopback binding should be tracked separately.Validation:
mise run pre-commit,mise run test, andmise run ciall pass locally.- addedstate:pr-openedPR has been opened for this issuePR has been opened for this issueand removedstate:agent-readyApproved for agent implementationApproved for agent implementationstate:in-progressWork is currently in progressWork is currently in progress
on Jul 3, 2026 This issue has had no activity for 14 days and is now marked stale. It may be closed in 7 days if there is no further activity. Comment or remove the state:stale label to keep it open.
- addedstate:staleInactive item at risk of automatic closure.Inactive item at risk of automatic closure.
on Jul 18, 2026
Agent Diagnostic
openshell.specmakes Podman a weak dependency for the baseopenshellpackage withRecommends: podman.openshell.specmakes Podman a hard dependency for theopenshell-gatewaysubpackage withRequires: podman.After=podman.socketandWants=podman.socket.deploy/rpm/gateway.toml.defaultseedscompute_drivers = ["podman"].install.shdownloads and installs bothopenshellandopenshell-gatewayRPMs, then starts the user gateway.Description
Actual behavior: Installing
openshell-gatewayv0.0.68 via RPM on a Rocky 8 host that already uses Docker fails during dependency resolution because the gateway RPM declares a hard dependency on Podman.The observed failure is:
Podman pulls in
runc, which conflicts with thecontainerd.iopackage provided by Docker'sdocker-ce-stablerepo. This blocks installation on hosts where Docker is already the standard container runtime.Expected behavior: The RPM gateway package should be installable on hosts that already have Docker available. Podman should not be required at package install time.
If the selected runtime is unavailable or misconfigured, OpenShell should fail clearly at gateway startup or sandbox creation time, not during package-manager dependency resolution.
Reproduction Steps
docker-ce-stable.dnfattempts to installopenshell-gatewayand solveRequires: podman.containerd.io.Environment
install.shLogs
Proposed Fix
Make the RPM/package-manager path support Docker hosts without requiring Podman.
Likely implementation pieces:
openshell-gatewayRPM metadata so Podman is not a hardRequires.compute_drivers = ["podman"].After=podman.socketandWants=podman.socketin the RPM user unit so the service does not implicitly depend on Podman when Docker is selected.Agent-First Checklist