Skip to content

Use mDNS hostname as launchd label and CLI connection name - #289

Merged
nirs merged 2 commits into
mainfrom
docs-use-mdns-name
Aug 31, 2026
Merged

nirs merged 2 commits into
mainfrom
docs-use-mdns-name

Conversation

@nirs

@nirs nirs commented Aug 31, 2026 •

Copy link
Copy Markdown
Owner

Starting and using a VM required two different names:

launchctl start local.docker
ssh root@docker.local

The launchd Label was reverse-DNS (local.$VM_NAME) while the VM's mDNS name is $VM_NAME.local. launchd.plist(5) only recommends naming the plist file <Label>.plist; the Label itself is an independent identifier. Keep the plist at ~/Library/LaunchAgents/local.$VM_NAME.plist and set the Label to the mDNS hostname.

Use the same name for the Docker context and podman system connection, so start, SSH, and the container CLI all share one identifier:

launchctl start docker.local
ssh root@docker.local
docker context use docker.local

In the podman benchmarks, iterate the full names instead of stitching prefixes and suffixes in the loop body. Prefix CONTAINERS_MACHINE_PROVIDER on the commands that need it instead of exporting it into the shell.

After dnf update on Fedora 44, podman -c fails with:

Error: unable to connect to Podman socket: Get "http://d/v6.1.0/libpod/_ping":
ssh: rejected: connect failed (open failed)

Fedora selinux-policy 44.6 dropped the permissive type for sshd_session_t. SSH stream-local forwarding to /run/podman/podman.sock is denied:

sshd_session_t → var_run_t : sock_file { write }
sshd_session_t → container_runtime_t : unix_stream_socket { connectto }

The podman tutorial now shows that failure and installs a local CIL module over SSH with those two allows. The module is stored in the guest policy store, so it survives reboot. It is not in cloud-init.

Starting and using a VM required two different names:

    launchctl start local.docker
    ssh root@docker.local

The launchd Label was reverse-DNS (`local.$VM_NAME`) while the VM's
mDNS name is `$VM_NAME.local`. launchd.plist(5) only recommends naming
the plist file `<Label>.plist`; the Label itself is an independent
identifier. Keep the plist at `~/Library/LaunchAgents/local.$VM_NAME.plist`
and set the Label to the mDNS hostname.

Use the same name for the Docker context and podman system connection,
so start, SSH, and the container CLI all share one identifier:

    launchctl start docker.local
    ssh root@docker.local
    docker context use docker.local

In the podman benchmarks, iterate the full names instead of stitching
prefixes and suffixes in the loop body. Prefix CONTAINERS_MACHINE_PROVIDER
on the commands that need it instead of exporting it into the shell.
@nirs
nirs force-pushed the docs-use-mdns-name branch 2 times, most recently from 0915358 to 286ba02 Compare August 31, 2026 17:10
After `dnf update`, `podman -c` fails with:

    Error: unable to connect to Podman socket: Get "http://d/v6.1.0/libpod/_ping":
    ssh: rejected: connect failed (open failed)

Fedora selinux-policy 44.6 dropped the permissive type for
`sshd_session_t`, so SSH stream-local forwarding cannot write
`/run/podman/podman.sock`. Show the failure and install a local
module over SSH that allows only this access. The module is stored
in the guest policy store, so it survives reboot. It is not in
cloud-init, so it can be inspected and retried while debugging.
@nirs
nirs force-pushed the docs-use-mdns-name branch from 286ba02 to fa0a8fa Compare August 31, 2026 17:55
@nirs nirs added this to the v0.14.0 milestone Aug 31, 2026
@nirs
nirs merged commit 2ce932f into main Aug 31, 2026
12 checks passed
@nirs
nirs deleted the docs-use-mdns-name branch August 31, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant