podman v5.5.0-rc1 版本更新介绍
发布日期: 2025-04-24
版本号: v5.5.0-rc1
Podman 新版本引入了多项功能增强与改进,主要包括:新增
podman machine cp命令用于在虚拟机间复制文件,以及podman artifact extract命令用于提取 OCI 制品内容。podman create、run和pod pod create的--mount选项现支持挂载 OCI 制品,podman artifact add增加了--append和--file-type选项,podman artifact rm支持--all删除所有制品。多个过滤命令(如pause、ps、rm等)新增command过滤器,podman exec支持通过--cidfile指定容器。podman kube generate和play支持保留容器 PID 限制的注解。Quadlet 配置文件新增了多项支持,包括内存限制、重试机制、主机名设置等。此外,Podman 现在生成秘密操作事件,并新增--cdi-spec-dir全局选项。podman build增加--inherit-labels选项,podman update支持修改环境变量。在破坏性变更方面,由于 Docker API 类型变化,REST API 的 Go 绑定中有两处小型不兼容调整。其他变更包括构建要求提升至 Go 1.23、健康检查性能优化、容器停止顺序改进、默认暂停镜像替换为仅含catatonit的根文件系统,以及安全加固等。本次更新还修复了众多错误,涉及健康检查运行异常、卷挂载问题、路径处理错误、命令输出不准确等多个方面,并更新了 Buildah 和相关容器库的版本。
更新内容 (中文)
功能特性
- 新增命令
podman machine cp,用于将文件复制到运行中的podman machine虚拟机。 - 新增命令
podman artifact extract,用于将 OCI 制品的全部或部分内容复制到磁盘指定位置。 podman create、podman run和podman pod create的--mount选项现支持新的挂载类型--mount type=artifact,可将 OCI 制品挂载到容器中。podman artifact add命令新增两个选项:--append(将新文件添加到现有制品)和--file-type(指定添加文件的 MIME 类型)(#25884)。podman artifact rm命令新增选项--all,用于删除本地存储中的所有制品。podman pause、podman ps、podman restart、podman rm、podman start、podman stop和podman unpause的--filter选项现支持新的过滤器command,可根据容器中运行命令的首个元素(argv[0])进行过滤。podman exec命令现支持新选项--cidfile,可通过文件指定要执行命令的容器 ID(#21256)。podman kube generate和podman kube play命令现支持新注解io.podman.annotation.pids-limit/$containername,可在kube generate和kube play之间保留容器的 PID 限制(#24418)。- Quadlet
.container单元现支持三个新键:Memory=(设置创建容器的最大内存)、ReloadCmd(通过 systemdExecReload执行命令)和ReloadSignal(通过 systemdExecReload以指定信号终止容器)(#22036)。 - Quadlet
.container、.image和.build单元现支持两个新键:Retry(拉取镜像失败时的重试次数)和RetryDelay(重试间隔时间)(#25109)。 - Quadlet
.pod单元现支持新键HostName=,用于设置 pod 的主机名(#25639)。 - Quadlet 文件的
Install部分现支持新选项UpheldBy,对应 systemd 的Upholds选项。 - 指定为 systemd 依赖的 Quadlet 单元名称现会自动转换(例如
Wants=my.container现在有效)。 - Podman 现在会为密钥的创建和删除生成事件(#24030)。
- Podman 新增全局选项
--cdi-spec-dir,用于为 CDI 加载器指定 CDI 规范的额外搜索路径(#18292 和 #25691)。 podman build命令现支持新选项--inherit-labels(默认为 true),用于控制是否从基础镜像或基础阶段继承标签。podman update命令现支持两个新选项:--env和--unsetenv,用于修改现有容器的环境变量(#24875)。
破坏性变更
- 由于 Docker API 类型的变更,REST API 的 Go 绑定中存在两处小型破坏性变更:
containers.Commit()函数现在返回内容相同的新结构体(types.IDResponse);containers.ExecCreate函数的handlers.ExecCreateConfig参数现在包含不同的嵌入式结构体,可能需要调整赋值方式。
变更
- Podman 现在要求至少使用 Go 1.23 进行构建。
- 健康检查机制已重构,以尽可能减少数据库写入,显著提升了同时运行大量健康检查系统的性能。
- 健康检查现新增状态
stopped,当健康检查执行的容器在检查完成前停止时报告该状态(#25276)。 - Pod 中的容器现在会根据依赖关系按顺序停止,基础容器最后停止,防止应用容器因基础容器过早停止而丢失网络。
- 由于自动安装的处理挑战,Windows 安装程序不再安装 WSLv2 或 Hyper-V。
- Quadlet 现在会在跳过行时打印警告,以帮助识别格式错误的 Quadlet 文件(#25339)。
- 不再允许创建宿主机挂载到虚拟机
/tmp目录的podman machine虚拟机(#18230)。 podman logs命令现允许在容器名称后指定选项(例如podman logs $containername --follow)(#25653)。- Podman 默认不再为 pod 基础容器和服务容器使用 pause 镜像,转而使用仅包含
catatonit二进制文件的根文件系统(#23292)。 podman system reset命令不再删除用户的podman.sockAPI 套接字。- 使用 Netavark v1.15 或更高版本时,非默认网络中的容器将不再添加默认搜索域
dns.podman,但解析此类名称的查询仍可正常工作。 - 停止 Quadlet
.network单元现会删除该网络(如果没有容器正在使用)(#23678)。 - 为了安全加固,容器中默认屏蔽
/proc/interrupts和/sys/devices/system/cpu/$CPU/thermal_throttle路径(#25634)。
错误修复
- 修复了容器暂停时健康检查仍会运行的问题(#24590)。
- 修复了 Windows 上的远程 Podman 客户端无法将单字符名称的命名卷挂载到容器的问题(#25218)。
- 修复了在未启用
CAP_SYS_ADMIN的情况下挂载镜像时可能出现的 panic 问题(#25241)。 - 修复了设置健康检查时 Podman 不会报告错误的问题(#25034)。
- 修复了
podman exec命令除非通过--user选项明确指定用户,否则不会添加执行会话用户的附加组的问题(#25610)。 - 修复了
podman network connect和podman network disconnect命令期间的错误可能导致数据库错误,进而导致容器podman inspect失败的问题。 - 修复了
podman kube generate命令未正确生成使用子路径的卷挂载 YAML 的问题。 - 修复了
podman system df命令可能显示负的可回收空间大小的问题。 - 修复了使用
podman machine ssh命令访问非默认虚拟机(podman-machine-default)的 rootfulpodman machine虚拟机时,会将用户置于非 root shell 的问题(#25332)。 - 修复了
podman machine init在尝试创建内存大于系统的机器时,会在错误信息中报告无意义内存值的问题。 - 修复了 Windows 上远程 Podman 客户端的
podman cp命令因 Windows 路径处理不当而经常无法将文件复制到容器的问题(#14862)。 - 修复了
podman container clone命令未将健康检查设置正确复制到新容器的问题(#21630)。 - 修复了
podman kube play命令无法启动空 pod 的问题(#25786)。 - 修复了
podman volume ls命令在没有卷时不输出表头的问题(#25911)。 - 修复了除非在创建容器时指定
--health-cmd选项,否则无法覆盖容器镜像提供的健康检查配置的问题(#20212)。 - 修复了
podman create和podman run的--user选项无法与通过--hostuser选项添加的容器用户一起使用的问题(#25805)。
API
- 修复了 Podman 以 rootless 模式运行时,容器兼容创建 API 忽略请求中指定的 ulimits 的问题(#25881)。
其他
- 已静默 REST API Go 绑定中
ExecStartAndAttach()函数的错误报告,该函数在 stdin 在执行会话停止后被使用时会错误地报告错误(#25344)。 - 将 Buildah 更新至 v1.40.0
- 将 containers/common 库更新至 v0.63.0
- 将 containers/image 库更新至 v5.35.0
- 将 containers/storage 库更新至 v1.58.0
更新内容 (原始)
Features
- A new command has been added,
podman machine cp, to copy files into a runningpodman machineVM. - A new command has been added,
podman artifact extract, to copy some or all of the contents of an OCI artifact to a location on disk. - The
--mountoption topodman create,podman run, andpodman pod createnow supports a new mount type,--mount type=artifact, to mount OCI artifacts into containers. - The
podman artifact addcommand now features two new options,--append(to add new files to an existing artifact) and--file-type(to specify the MIME type of the file added to the artifact) (#25884). - The
podman artifact rmcommand now features a new option,--all, to remove all artifacts in the local store. - The
--filteroption topodman pause,podman ps,podman restart,podman rm,podman start,podman stop, andpodman unpausenow accepts a new filter,command, which filters on the first element (argv[0]) of the command run in the container. - The
podman execcommand now supports a new option,--cidfile, to specify the ID of the container to exec into via a file (#21256). - The
podman kube generateandpodman kube playcommands now supports a new annotation,io.podman.annotation.pids-limit/$containername, preserving the PID limit for containers acrosskube generateandkube play(#24418). - Quadlet
.containerunits now support three new keys,Memory=(set maximum memory for the created container),ReloadCmd(execute a command via systemdExecReload), andReloadSignal(kill the container with the given signal via systemdExecReload) (#22036). - Quadlet
.container,.image, and.buildunits now support two new keys,Retry(number of times to retry pulling image on failure) andRetryDelay(delay between retries) (#25109). - Quadlet
.podunits now support a new key,HostName=, to set the pod’s hostname (#25639). - Quadlet files now support a new option,
UpheldBy, in theInstallsection, corresponding to the systemdUpholdsoption. - The names of Quadlet units specified as systemd dependencies are now automatically translated - e.g.
Wants=my.containeris now valid. - Podman now generates events for the creation and removal of secrets (#24030).
- A new global option has been added to Podman,
--cdi-spec-dir, to specify additional search paths for CDI specs to the CDI loader (#18292 and #25691). - The
podman buildcommand now supports a new option,--inherit-labels(defaults to true), which controls whether labels are inherited from the base image or base stages. - The
podman updatecommand now supports two new options,--envand--unsetenv, to alter the environment variables of existing containers (#24875).
Breaking Changes
- Due to changes in Docker API types, two small breaking changes have been made in the Go bindings for the REST API. The
containers.Commit()function now returns a new struct (types.IDResponse) with identical contents, and thecontainers.ExecCreatefunction’shandlers.ExecCreateConfigparameter now contains a different embedded struct, potentially requiring changes to how it is assigned to.
Changes
- Podman now requires at least Go 1.23 to build.
- Healthchecks have been refactored to avoid writing to the database as much as possible, greatly improving performance on systems with many simultaneous healthchecks running.
- Healthchecks now have a new status,
stopped, which is reported if the container the healthcheck was run on stopped before the check could be completed (#25276). - Containers in pods are now stopped in order based on their dependencies, with the infra container being stopped last, preventing application containers from losing networking before they are stopped due to the infra container stopping prematurely.
- Due to challenges with handling automatic installation, the Windows installer no longer installs WSLv2 or Hyper-V.
- Quadlet will now print warnings when skipping lines to help identify malformed Quadlet files (#25339).
- Creating
podman machineVMs with a host mount over the VM’s/tmpdirectory is no longer allowed (#18230). - The
podman logscommand now allows options to be specified after the container name (e.g.podman logs $containername --follow) (#25653). - Podman, by default, no longer uses a pause image for pod infra and service containers. Instead, a root filesystem containing only the
catatonitbinary will be used (#23292). - The
podman system resetcommand no longer removes the user’spodman.sockAPI socket. - When using Netavark v1.15 and higher, containers in non-default networks will no longer have the default search domain
dns.podmanadded. Queries resolving such names will still work. - Stopping a Quadlet
.networkunit will now delete the network (if no containers are actively using it) (#23678). - For security hardening, the
/proc/interruptsand/sys/devices/system/cpu/$CPU/thermal_throttlepaths are now masked by default in containers (#25634).
Bugfixes
- Fixed a bug where healthchecks would still run while a container was paused (#24590).
- Fixed a bug where the remote Podman client on Windows could not mount named volumes with a single-character name into containers (#25218).
- Fixed a bug where mounting an image could panic when run without
CAP_SYS_ADMIN(#25241). - Fixed a bug where Podman would not report errors when setting up healthchecks (#25034).
- Fixed a bug where the
podman execcommand would not add the additional groups of the user the exec session was run as unless the user was explicitly added with the--useroption (#25610). - Fixed a bug where errors during the
podman network connectandpodman network disconnectcommands could create errors in the database which would causepodman inspecton the container to fail. - Fixed a bug where the
podman kube generatecommand did not correctly generate YAML for volume mounts using a subpath. - Fixed a bug where the
podman system dfcommand could show a negative reclaimable size. - Fixed a bug where accessing a rootful
podman machineVM that was notpodman-machine-default(the default VM) with thepodman machine sshcommand would put the user into the rootless shell (#25332). - Fixed a bug where the
podman machine initwould report nonsensical memory values in error messages when trying to create a machine with more memory than the system. - Fixed a bug where the remote Podman client’s
podman cpcommand would, on Windows, often fail to copy files into the container due to improper handling of Windows paths (#14862). - Fixed a bug where the
podman container clonecommand did not correctly copy healthcheck settings to the new container (#21630). - Fixed a bug where the
podman kube playcommand would fail to start empty pods (#25786). - Fixed a bug where the
podman volume lscommand did not output headers when no volumes were present (#25911). - Fixed a bug where healthcheck configuration provided by a container’s image could not be overridden unless the
--health-cmdoption was specified when creating the container (#20212). - Fixed a bug where the
--useroption topodman createandpodman runcould not be used with users added to the container by the--hostuseroption (#25805).
API
- Fixed a bug where the Compat Create API for Containers ignored ulimits specified in the request when Podman was run rootless (#25881).
Misc
- Erroneous errors from the
ExecStartAndAttach()function in the Go bindings for the REST API have been silenced, where the function would incorrectly report errors when stdin was consumed after the exec session was stopped (#25344). - Updated Buildah to v1.40.0
- Updated the containers/common library to v0.63.0
- Updated the containers/image library to v5.35.0
- Updated the containers/storage library to v1.58.0
下载链接
- podman-5.5.0-rc1-setup.exe
- podman-installer-macos-amd64.pkg
- podman-installer-macos-arm64.pkg
- podman-installer-macos-universal.pkg
- podman-remote-release-darwin_amd64.zip
- podman-remote-release-darwin_arm64.zip
- podman-remote-release-windows_amd64.zip
- podman-remote-static-linux_amd64.tar.gz
- podman-remote-static-linux_arm64.tar.gz
- shasums