Use mDNS hostname as launchd label and CLI connection name - #289
Merged
Merged
Conversation
Starting and using a VM required two different names:
launchctl start local.docker
ssh root@docker.local
The launchd Label was reverse-DNS (`local.$VM_NAME`) while the VM's
mDNS name is `$VM_NAME.local`. launchd.plist(5) only recommends naming
the plist file `<Label>.plist`; the Label itself is an independent
identifier. Keep the plist at `~/Library/LaunchAgents/local.$VM_NAME.plist`
and set the Label to the mDNS hostname.
Use the same name for the Docker context and podman system connection,
so start, SSH, and the container CLI all share one identifier:
launchctl start docker.local
ssh root@docker.local
docker context use docker.local
In the podman benchmarks, iterate the full names instead of stitching
prefixes and suffixes in the loop body. Prefix CONTAINERS_MACHINE_PROVIDER
on the commands that need it instead of exporting it into the shell.
nirs
force-pushed
the
docs-use-mdns-name
branch
2 times, most recently
from
August 31, 2026 17:10
0915358 to
286ba02
Compare
After `dnf update`, `podman -c` fails with:
Error: unable to connect to Podman socket: Get "http://d/v6.1.0/libpod/_ping":
ssh: rejected: connect failed (open failed)
Fedora selinux-policy 44.6 dropped the permissive type for
`sshd_session_t`, so SSH stream-local forwarding cannot write
`/run/podman/podman.sock`. Show the failure and install a local
module over SSH that allows only this access. The module is stored
in the guest policy store, so it survives reboot. It is not in
cloud-init, so it can be inspected and retried while debugging.
nirs
force-pushed
the
docs-use-mdns-name
branch
from
August 31, 2026 17:55
286ba02 to
fa0a8fa
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Starting and using a VM required two different names:
The launchd Label was reverse-DNS (
local.$VM_NAME) while the VM's mDNS name is$VM_NAME.local. launchd.plist(5) only recommends naming the plist file<Label>.plist; the Label itself is an independent identifier. Keep the plist at~/Library/LaunchAgents/local.$VM_NAME.plistand set the Label to the mDNS hostname.Use the same name for the Docker context and podman system connection, so start, SSH, and the container CLI all share one identifier:
In the podman benchmarks, iterate the full names instead of stitching prefixes and suffixes in the loop body. Prefix CONTAINERS_MACHINE_PROVIDER on the commands that need it instead of exporting it into the shell.
After
dnf updateon Fedora 44,podman -cfails with:Fedora selinux-policy 44.6 dropped the permissive type for
sshd_session_t. SSH stream-local forwarding to/run/podman/podman.sockis denied:The podman tutorial now shows that failure and installs a local CIL module over SSH with those two allows. The module is stored in the guest policy store, so it survives reboot. It is not in cloud-init.