Skip to content

docs: add timesync and guest agent config - #290

Merged
nirs merged 3 commits into
mainfrom
time-sync
Sep 5, 2026
Merged

nirs merged 3 commits into
mainfrom
time-sync

Conversation

@nirs

@nirs nirs commented Sep 5, 2026 •

Copy link
Copy Markdown
Owner

Configure qemu-guest-agent to listen on vsock port 1234 and add
--timesync vsockPort=1234 to the vfkit and krunkit commands in the
podman and docker tutorials. This syncs the guest clock after the
host wakes from sleep.

The default qemu-guest-agent.service depends on a virtio-serial
device that neither vfkit nor krunkit provide. The service would
never start since the device does not exist. We replace it with a
unit file in /etc/systemd/system/ that uses vsock and starts via
multi-user.target. The runcmd uses "disable" then "enable --now"
to remove the stale symlinks from the original device target and
create new ones for multi-user.target.

On Fedora (podman tutorial), the SELinux policy for virt_qemu_ga_t
only allows virtio-serial communication. We install a CIL policy
module to allow vsock socket operations, matching the policy used
by podman-machine-os. On Ubuntu (docker tutorial), AppArmor does
not restrict vsock access so no policy changes are needed, but
qemu-guest-agent must be added to the cloud-init packages list
since it is not pre-installed.

When vfkit/krunkit starts with --timesync vsockPort=1234, it
monitors the host for sleep/resume events. After resume, it
connects to the guest agent over vsock port 1234 and sends the
current host time to correct the guest clock, which stopped
during host sleep.

@nirs
nirs force-pushed the time-sync branch 4 times, most recently from 484b499 to 3b3a6d2 Compare September 5, 2026 19:38
Configure qemu-guest-agent to listen on vsock port 1234 and add
--timesync vsockPort=1234 to the vfkit command. This syncs the
guest clock after the host wakes from sleep.

The default qemu-guest-agent.service on Fedora depends on a
virtio-serial device that vfkit does not provide:

    [Unit]
    BindsTo=dev-virtio\x2dports-org.qemu.guest_agent.0.device

    [Install]
    WantedBy=dev-virtio\x2dports-org.qemu.guest_agent.0.device

The service would never start since the device does not exist.
We replace it with a unit file in /etc/systemd/system/ that uses
vsock and starts via multi-user.target. The runcmd uses "disable"
then "enable --now" to remove the stale symlinks from the original
device target and create new ones for multi-user.target.

The Fedora SELinux policy for virt_qemu_ga_t only allows
virtio-serial communication. We install a CIL policy module to
allow vsock socket operations, matching the policy used by
podman-machine-os.

When vfkit starts with --timesync vsockPort=1234, it monitors the
host for sleep/resume events. After resume, vfkit connects to the
guest agent over vsock port 1234 and sends the current host time
to correct the guest clock, which stopped during host sleep.
Same configuration as vfkit — krunkit supports the same --timesync
vsockPort=1234 option.
@nirs nirs changed the title docs/podman: add timesync and guest agent config for vfkit docs/podman: add timesync and guest agent config Sep 5, 2026
Same approach as the podman tutorial. Unlike Fedora, Ubuntu
minimal does not ship qemu-guest-agent, so we add it to the
cloud-init packages list. No SELinux policy is needed since
Ubuntu uses AppArmor which does not restrict vsock access.
@nirs nirs changed the title docs/podman: add timesync and guest agent config docs: add timesync and guest agent config Sep 5, 2026
@nirs
nirs merged commit 101f109 into main Sep 5, 2026
12 checks passed
@nirs
nirs deleted the time-sync branch September 5, 2026 20:46
@nirs nirs added this to the v0.14.0 milestone Sep 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant