Podman is the container foundation, Portainer CE is the web interface onto it, running as a container on the very engine it manages. This is what the separate portainer module already did, so it is retired rather than duplicated. Two sockets on purpose: the rootful one is the Docker-compatible API Portainer drives (it does not support rootless), the rootless user socket is for people who ssh in and run containers by hand — which was the original podman module's point and is worth keeping. An explicit proxyDomain lets the module publish at the environment's own domain instead of <module>.<environment-domain>, making it that environment's gateway. DESIGN.md keeps the Cockpit identity analysis: it is the reason for the change, and anyone proposing 'just put Cockpit behind forward-auth' should read it.
40 lines
1.3 KiB
JSON
40 lines
1.3 KiB
JSON
{
|
|
"description": "Podman container host with a Portainer CE web console — create, start, stop and inspect OCI containers on this VM and on agent hosts in the same zone, signed in with TAPPaaS identity",
|
|
"version": "0.2.0",
|
|
"appVersion": "5.4",
|
|
"releaseDate": "2026-08-25",
|
|
"maintainer": "@larsrossen",
|
|
"status": "Development",
|
|
"vmname": "podman",
|
|
"vmid": 812,
|
|
"vmtag": "TAPPaaS,MakerFLOSS,Containers",
|
|
"ports": [
|
|
{ "port": 9443, "protocol": "TCP", "description": "Portainer web console (HTTPS)" },
|
|
{ "port": 8000, "protocol": "TCP", "description": "Edge agent tunnel (inbound from edge agents)" }
|
|
],
|
|
"dependsOn": ["cluster:vm", "templates:debian", "backup:vm", "network:proxy", "identity:identity"],
|
|
"provides": [],
|
|
"identity": {
|
|
"oidcRedirectPaths": ["/"],
|
|
"secretsEnv": "/etc/secrets/podman.env"
|
|
},
|
|
"config": {
|
|
"cluster:vm": {
|
|
"bios": "seabios",
|
|
"ostype": "l26",
|
|
"cores": 2,
|
|
"memory": "2048",
|
|
"diskSize": "32G",
|
|
"storage": "tanka1",
|
|
"imageType": "img",
|
|
"image": "debian-13-generic-amd64.qcow2",
|
|
"imageLocation": "https://cdimage.debian.org/cdimage/cloud/trixie/latest",
|
|
"cloudInit": "true",
|
|
"bridge0": "lan"
|
|
},
|
|
"network:proxy": {
|
|
"proxyPort": 9443,
|
|
"proxyUpstreamTls": true
|
|
}
|
|
}
|
|
}
|