)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":17669,"name":"Doug Szumski","email":"doug@stackhpc.com","username":"DougSzumski"},"change_message_id":"52b8e369a3d675da4a0e3e9338848765b1431bf9","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"c4a9a803_79b82f61","updated":"2026-06-11 09:51:58.000000000","message":"Many thanks @cid@gr-oss.io - this looks excellent.","commit_id":"74dfb4eee0dec0804259c7e0038c585be7af655f"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"783812228380f53f04823d0c0583c5dd5f085e51","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"82452890_c9305b25","in_reply_to":"c4a9a803_79b82f61","updated":"2026-06-15 12:20:45.000000000","message":"\\o/","commit_id":"74dfb4eee0dec0804259c7e0038c585be7af655f"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"3def7fa9fcbaa5d33b59c26ebe2a87e62f0ab4a2","unresolved":true,"context_lines":[],"source_content_type":"","patch_set":2,"id":"9e6d82dc_93344895","updated":"2026-06-25 17:02:51.000000000","message":"I really, really don\u0027t want to call this driver \"docker\" or \"podman\" especially since the other ones use it. Really that\u0027s the only blocking feedback I have at this point -- the \"log Denial of Service\" pointed out is unlikely to be a viable attack vector but we can run the numbers if we wanna be sure.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"deb003fcacc09fd3f3bcd826bb32834309cdf687","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"b52c9721_e732b085","updated":"2026-06-25 17:10:20.000000000","message":"Overall, I think this is a good addition. I\u0027m going to ask Steve Baker to take a look.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"4fccf527f33b142d7473e202399ee4a5257ace29","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":2,"id":"3d163409_b245f29b","updated":"2026-06-23 02:53:25.000000000","message":"recheck - could not recreate linter error locally.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"}],"specs/approved/docker-console-container-provider.rst":[{"author":{"_account_id":36770,"name":"cid","display_name":"cid","email":"cid@gr-oss.io","username":"cidelight","status":"@gr-oss upstream: Doing good IRONIC things..."},"change_message_id":"86431073fbddfd69a1fbf188c1ce89d22a9e3791","unresolved":true,"context_lines":[{"line_number":405,"context_line":"------------------"},{"line_number":406,"context_line":""},{"line_number":407,"context_line":"Per-session cost is identical to the existing providers: one container"},{"line_number":408,"context_line":"(~300MB memory) and one host TCP port per active console. Each console"},{"line_number":409,"context_line":"start/stop adds a handful of short-lived CLI invocations against a local"},{"line_number":410,"context_line":"engine socket. ``stop_all_containers()`` performs one label-filtered list"},{"line_number":411,"context_line":"plus removals at conductor startup and shutdown. The engine daemon is"}],"source_content_type":"text/x-rst","patch_set":1,"id":"7de29d6e_302be736","line":408,"range":{"start_line":408,"start_character":1,"end_line":408,"end_character":14},"updated":"2026-06-10 18:48:31.000000000","message":"per the Graphical Console Support feature documentation.","commit_id":"74dfb4eee0dec0804259c7e0038c585be7af655f"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"3def7fa9fcbaa5d33b59c26ebe2a87e62f0ab4a2","unresolved":true,"context_lines":[{"line_number":14,"context_line":"session, managed through a pluggable console container provider. The"},{"line_number":15,"context_line":"existing ``systemd`` and ``kubernetes`` providers are unusable when"},{"line_number":16,"context_line":"``ironic-conductor`` itself runs in a Docker or Podman container. This"},{"line_number":17,"context_line":"spec adds a ``docker`` provider which manages console containers directly"},{"line_number":18,"context_line":"through a Docker compatible container engine."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Problem description"}],"source_content_type":"text/x-rst","patch_set":2,"id":"d3e40180_11d37b7b","line":17,"updated":"2026-06-25 17:02:51.000000000","message":"Ideally, we would have a name for this provider which is not docker/podman specific since both are compatible. Maybe something like \"direct\" or \"container-spawn\" or \"cli\" or something like that?","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":14,"context_line":"session, managed through a pluggable console container provider. The"},{"line_number":15,"context_line":"existing ``systemd`` and ``kubernetes`` providers are unusable when"},{"line_number":16,"context_line":"``ironic-conductor`` itself runs in a Docker or Podman container. This"},{"line_number":17,"context_line":"spec adds a ``docker`` provider which manages console containers directly"},{"line_number":18,"context_line":"through a Docker compatible container engine."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Problem description"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a7722217_840bafd8","line":17,"in_reply_to":"55f28bb5_23f24d93","updated":"2026-06-28 22:51:01.000000000","message":"We\u0027ve had to do docker name purges in the past due to trademark rugpulls, so I think the concern is real.\n\nI\u0027d suggest a \"container\" container provider, with the config options being prefixed with \"container_\". Yeah I know it is generic but I think this is the one provider which justifies it. Its documentation will clearly say this is for managing graphical consoles with \"docker\" or \"podman\" commands.\n\n\"direct\" is an appealing colour for a bikeshed too.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"b06f144358e11ee93c6cae00552389630636c622","unresolved":true,"context_lines":[{"line_number":14,"context_line":"session, managed through a pluggable console container provider. The"},{"line_number":15,"context_line":"existing ``systemd`` and ``kubernetes`` providers are unusable when"},{"line_number":16,"context_line":"``ironic-conductor`` itself runs in a Docker or Podman container. This"},{"line_number":17,"context_line":"spec adds a ``docker`` provider which manages console containers directly"},{"line_number":18,"context_line":"through a Docker compatible container engine."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Problem description"}],"source_content_type":"text/x-rst","patch_set":2,"id":"55f28bb5_23f24d93","line":17,"in_reply_to":"a4c57313_60205bf3","updated":"2026-06-25 19:19:47.000000000","message":"My issue with the name is mainly twofold:\n- using the (tm) of a company that has done license rugpulls\n- it\u0027s descriptive of the container runtime -- but not the method to orchestrate the container runtime. The other interfaces in this category describe the orchestration method used.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"56d2c87ae9e07ca67bac7a36fab782af4159a654","unresolved":true,"context_lines":[{"line_number":14,"context_line":"session, managed through a pluggable console container provider. The"},{"line_number":15,"context_line":"existing ``systemd`` and ``kubernetes`` providers are unusable when"},{"line_number":16,"context_line":"``ironic-conductor`` itself runs in a Docker or Podman container. This"},{"line_number":17,"context_line":"spec adds a ``docker`` provider which manages console containers directly"},{"line_number":18,"context_line":"through a Docker compatible container engine."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Problem description"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4bffe6a0_9032a0c1","line":17,"in_reply_to":"a7722217_840bafd8","updated":"2026-06-29 04:03:44.000000000","message":"Other potential provider names: \"engine\", \"spawn\"","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"be8114329a1f769f5dfcb99c2bcc5da211c6fe3d","unresolved":true,"context_lines":[{"line_number":14,"context_line":"session, managed through a pluggable console container provider. The"},{"line_number":15,"context_line":"existing ``systemd`` and ``kubernetes`` providers are unusable when"},{"line_number":16,"context_line":"``ironic-conductor`` itself runs in a Docker or Podman container. This"},{"line_number":17,"context_line":"spec adds a ``docker`` provider which manages console containers directly"},{"line_number":18,"context_line":"through a Docker compatible container engine."},{"line_number":19,"context_line":""},{"line_number":20,"context_line":"Problem description"}],"source_content_type":"text/x-rst","patch_set":2,"id":"a4c57313_60205bf3","line":17,"in_reply_to":"d3e40180_11d37b7b","updated":"2026-06-25 17:14:05.000000000","message":"I don\u0027t see this as an issue, but I\u0027ve seen podman not be perfectly compatible with docker in some cases.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":122,"context_line":"       --name ironic-console-\u003cnode uuid\u003e \\"},{"line_number":123,"context_line":"       --label org.openstack.ironic.console\u003dtrue \\"},{"line_number":124,"context_line":"       --label org.openstack.ironic.conductor\u003d\u003cCONF.host\u003e \\"},{"line_number":125,"context_line":"       --label org.openstack.ironic.node\u003d\u003cnode uuid\u003e \\"},{"line_number":126,"context_line":"       --publish \u003c[vnc]docker_publish_port\u003e \\"},{"line_number":127,"context_line":"       --pull \u003c[vnc]docker_pull_policy\u003e \\"},{"line_number":128,"context_line":"       --env APP\u003d\u003capp_name\u003e \\"}],"source_content_type":"text/x-rst","patch_set":2,"id":"296a63af_3db7d15e","line":125,"updated":"2026-06-28 22:51:01.000000000","message":"The template approach of kubernetes and systemd provider makes it easy to have an opinionated label policy. There is enough going on in this command that composing it with a template file may be appropriate. It would make [vnc]docker_pull_policy and [vnc]docker_extra_run_args unnecessary, and provide the kind of flexibility that some operators would need.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"3def7fa9fcbaa5d33b59c26ebe2a87e62f0ab4a2","unresolved":true,"context_lines":[{"line_number":178,"context_line":""},{"line_number":179,"context_line":"Containers are run without ``--rm`` so that the logs of a crashed or"},{"line_number":180,"context_line":"failed container remain inspectable; cleanup happens via the explicit"},{"line_number":181,"context_line":"removals above and via ``stop_all_containers()`` at conductor startup."},{"line_number":182,"context_line":""},{"line_number":183,"context_line":"No ``--restart`` policy is set: an engine or container restart would"},{"line_number":184,"context_line":"republish a new random host port that no longer matches the ``vnc_port``"}],"source_content_type":"text/x-rst","patch_set":2,"id":"d4bf95f4_e8e12a79","line":181,"updated":"2026-06-25 17:02:51.000000000","message":"If we had a really, really long-running conductor it\u0027s possible we\u0027ll run into space contraints.\n\nImagine this:\n- Automated process rebuilds the console container with seucrity updates from the OS in weekly CI job\n- Ironic conductor has uptime of 90 days and console is in heavy usage\n- How much disk space will be taken up by: a) container pulls (you get a fresh one every week, so we would have ~12) and b) container logs.\n\nI wonder if we need a periodic -- or at least documentation -- for operators to beware of this scenario. If we went this route, I\u0027d suggest in addition to encoding CONF.host into a label, we also encode \"startup_time\" as a label as well, so we can specifically remove container logs based on a TTL.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"be8114329a1f769f5dfcb99c2bcc5da211c6fe3d","unresolved":true,"context_lines":[{"line_number":178,"context_line":""},{"line_number":179,"context_line":"Containers are run without ``--rm`` so that the logs of a crashed or"},{"line_number":180,"context_line":"failed container remain inspectable; cleanup happens via the explicit"},{"line_number":181,"context_line":"removals above and via ``stop_all_containers()`` at conductor startup."},{"line_number":182,"context_line":""},{"line_number":183,"context_line":"No ``--restart`` policy is set: an engine or container restart would"},{"line_number":184,"context_line":"republish a new random host port that no longer matches the ``vnc_port``"}],"source_content_type":"text/x-rst","patch_set":2,"id":"7666e7f5_66b6837c","line":181,"in_reply_to":"d4bf95f4_e8e12a79","updated":"2026-06-25 17:14:05.000000000","message":"Great callout, I\u0027d suggest a documentation callout, or just make it configurable so that we run with --rm, and then if issues are encountered operators can remove the flag to collect more data.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":190,"context_line":"restarts; the ``org.openstack.ironic.console`` label gives operators a"},{"line_number":191,"context_line":"documented way to locate and purge orphans. Per-node serialization of"},{"line_number":192,"context_line":"start and stop is provided by the conductor\u0027s exclusive node lock, as for"},{"line_number":193,"context_line":"the existing providers; the provider itself holds no state."},{"line_number":194,"context_line":""},{"line_number":195,"context_line":"Engine selection and Podman support"},{"line_number":196,"context_line":"-----------------------------------"}],"source_content_type":"text/x-rst","patch_set":2,"id":"046e1d1f_8de01d2c","line":193,"updated":"2026-06-28 22:51:01.000000000","message":"There is a periodic task which stops containers for expired sessions. This paragraph has given me the idea that the periodic should really also be responsible for ending sessions when the container has stopped for whatever reason. So it keeps the state consistent in both directions.\n\nI raised this to track it https://bugs.launchpad.net/ironic/+bug/2158578","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":232,"context_line":"provider-prefix convention of the ``systemd_*`` and ``kubernetes_*``"},{"line_number":233,"context_line":"options:"},{"line_number":234,"context_line":""},{"line_number":235,"context_line":"``docker_executable`` (string, default ``docker``)"},{"line_number":236,"context_line":"  Name or absolute path of the Docker-compatible CLI binary. Set to"},{"line_number":237,"context_line":"  ``podman`` to use Podman\u0027s Docker-compatible CLI."},{"line_number":238,"context_line":""}],"source_content_type":"text/x-rst","patch_set":2,"id":"482b89ab_cbee0cc0","line":235,"updated":"2026-06-28 22:51:01.000000000","message":"Prefix all these options with container_ as per my suggestion at the top?","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":249,"context_line":"  bracketed (e.g. ``[2001:db8::1]::5900``), so deployments where"},{"line_number":250,"context_line":"  ``my_ip`` is IPv6 must set this option explicitly."},{"line_number":251,"context_line":""},{"line_number":252,"context_line":"``docker_pull_policy`` (string, default ``missing``)"},{"line_number":253,"context_line":"  Value for ``docker run --pull``; one of ``missing``, ``always`` or"},{"line_number":254,"context_line":"  ``never``."},{"line_number":255,"context_line":""},{"line_number":256,"context_line":"``docker_extra_run_args`` (list of strings, default empty)"},{"line_number":257,"context_line":"  Additional arguments appended to ``docker run``, for deployment-specific"},{"line_number":258,"context_line":"  needs such as ``--network``, resource limits (``--memory``, ``--cpus``)"},{"line_number":259,"context_line":"  or extra labels."},{"line_number":260,"context_line":""},{"line_number":261,"context_line":"The help text of ``[vnc]container_provider`` and ``[vnc]console_image``"},{"line_number":262,"context_line":"will be updated to document the ``docker`` provider. The existing"}],"source_content_type":"text/x-rst","patch_set":2,"id":"4a09c497_24904c8f","line":259,"range":{"start_line":252,"start_character":0,"end_line":259,"end_character":18},"updated":"2026-06-28 22:51:01.000000000","message":"Replace these with a templated command as suggested above?","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":4571,"name":"Steve Baker","email":"sbaker@redhat.com","username":"steve-stevebaker"},"change_message_id":"6f69a6cfc97f13c07db58bff5f9120b7e7dbfb50","unresolved":true,"context_lines":[{"line_number":270,"context_line":"endpoint until it returns 12 bytes of data (the length of an RFB"},{"line_number":271,"context_line":"ProtocolVersion greeting), is generic. It will be moved to"},{"line_number":272,"context_line":"``BaseConsoleContainer`` (or a small shared helper module) with behaviour"},{"line_number":273,"context_line":"unchanged, and reused by both the ``systemd`` and ``docker`` providers."},{"line_number":274,"context_line":""},{"line_number":275,"context_line":"Scope"},{"line_number":276,"context_line":"-----"}],"source_content_type":"text/x-rst","patch_set":2,"id":"9873829e_e738a5e5","line":273,"updated":"2026-06-28 22:51:01.000000000","message":"I do wonder if the kubernetes provider would benefit from this too","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":10342,"name":"Jay Faulkner","display_name":"JayF","email":"jay@jvf.cc","username":"JayF","status":"youtube.com/@oss-gr / podcast.gr-oss.io"},"change_message_id":"3def7fa9fcbaa5d33b59c26ebe2a87e62f0ab4a2","unresolved":true,"context_lines":[{"line_number":287,"context_line":"  Rejected: it adds a Python dependency for an optional feature, couples"},{"line_number":288,"context_line":"  Ironic to engine API versioning, and breaks with the in-tree precedent"},{"line_number":289,"context_line":"  of shelling out (``kubectl``, ``systemctl``, ``podman``). The CLI is"},{"line_number":290,"context_line":"  also the interface deployments can most easily constrain and audit."},{"line_number":291,"context_line":"* Add a dedicated ``podman`` provider now. Rejected for the initial"},{"line_number":292,"context_line":"  implementation: Podman\u0027s Docker compatibility makes it redundant, and"},{"line_number":293,"context_line":"  the RFE explicitly suggests supporting Docker first."}],"source_content_type":"text/x-rst","patch_set":2,"id":"fb460d20_a50685d4","line":290,"updated":"2026-06-25 17:02:51.000000000","message":"And these may have version-specific requirements: CLI gets us outta all that mess +1","commit_id":"f9aac336563e316914b849d785beee4897845c7b"},{"author":{"_account_id":11655,"name":"Julia Kreger","email":"juliaashleykreger@gmail.com","username":"jkreger","status":"Flying to the moon with a Jetpack!"},"change_message_id":"be8114329a1f769f5dfcb99c2bcc5da211c6fe3d","unresolved":true,"context_lines":[{"line_number":287,"context_line":"  Rejected: it adds a Python dependency for an optional feature, couples"},{"line_number":288,"context_line":"  Ironic to engine API versioning, and breaks with the in-tree precedent"},{"line_number":289,"context_line":"  of shelling out (``kubectl``, ``systemctl``, ``podman``). The CLI is"},{"line_number":290,"context_line":"  also the interface deployments can most easily constrain and audit."},{"line_number":291,"context_line":"* Add a dedicated ``podman`` provider now. Rejected for the initial"},{"line_number":292,"context_line":"  implementation: Podman\u0027s Docker compatibility makes it redundant, and"},{"line_number":293,"context_line":"  the RFE explicitly suggests supporting Docker first."}],"source_content_type":"text/x-rst","patch_set":2,"id":"4df2ca35_227bef08","line":290,"in_reply_to":"fb460d20_a50685d4","updated":"2026-06-25 17:14:05.000000000","message":"++ It shifts it, the CLI could still be an issue, but it is a more static surface.","commit_id":"f9aac336563e316914b849d785beee4897845c7b"}]}
