github.com/containers/podman/v5@v5.1.0-rc1/docs/source/markdown/podman-auto-update.1.md.in (about)

     1  % podman-auto-update 1
     2  
     3  ## NAME
     4  podman\-auto-update - Auto update containers according to their auto-update policy
     5  
     6  ## SYNOPSIS
     7  **podman auto-update** [*options*]
     8  
     9  ## DESCRIPTION
    10  **podman auto-update** pulls down new container images and restarts containers configured for auto updates.
    11  To make use of auto updates, the container or Kubernetes workloads must run inside a systemd unit.
    12  After a successful update of an image, the containers using the image get updated by restarting the systemd units they run in.
    13  Please refer to `quadlet(5)` on how to run Podman under systemd.
    14  
    15  To configure a container for auto updates, it must be created with the `io.containers.autoupdate` label or the `AutoUpdate` field in `quadlet(5)` with one of the following two values:
    16  
    17  * `registry`: If the label is present and set to `registry`, Podman reaches out to the corresponding registry to check if the image has been updated.
    18  The label `image` is an alternative to `registry` maintained for backwards compatibility.
    19  An image is considered updated if the digest in the local storage is different than the one of the remote image.
    20  If an image must be updated, Podman pulls it down and restarts the systemd unit executing the container.
    21  The registry policy requires a fully-qualified image reference (e.g., quay.io/podman/stable:latest) to be used to create the container.
    22  This enforcement is necessary to know which image to actually check and pull.
    23  If an image ID was used, Podman would not know which image to check/pull anymore.
    24  
    25  * `local`: If the autoupdate label is set to `local`, Podman compares the image digest of the container to the one in the local container storage.
    26  If they differ, the local image is considered to be newer and the systemd unit gets restarted.
    27  
    28  ### Auto Updates and Kubernetes YAML
    29  
    30  Podman supports auto updates for Kubernetes workloads.  The auto-update policy can be configured directly via `quadlet(5)` or inside the Kubernetes YAML with the Podman-specific annotations mentioned below:
    31  
    32  * `io.containers.autoupdate`: "registry|local" to apply the auto-update policy to all containers
    33  * `io.containers.autoupdate/$container`: "registry|local" to apply the auto-update policy to `$container` only
    34  * `io.containers.sdnotify`: "conmon|container" to apply the sdnotify policy to all containers
    35  * `io.containers.sdnotify/$container`: "conmon|container" to apply the sdnotify policy to `$container` only
    36  
    37  By default, the autoupdate policy is set to "disabled", the sdnotify policy is set to "conmon".
    38  
    39  ### Systemd Unit and Timer
    40  
    41  Podman ships with a `podman-auto-update.service` systemd unit. This unit is triggered daily at midnight by the `podman-auto-update.timer` systemd timer.
    42  The timer can be altered for custom time-based updates if desired.
    43  The unit can further be invoked by other systemd units (e.g., via the dependency tree) or manually via **systemctl start podman-auto-update.service**.
    44  
    45  ## OPTIONS
    46  
    47  @@option authfile
    48  
    49  Alternatively, the `io.containers.autoupdate.authfile` container label can be configured.  In that case, Podman will use the specified label's value instead.
    50  
    51  #### **--dry-run**
    52  
    53  Check for the availability of new images but do not perform any pull operation or restart any service or container.
    54  The `UPDATED` field indicates the availability of a new image with "pending".
    55  
    56  #### **--format**=*format*
    57  
    58  Change the default output format.  This can be of a supported type like 'json' or a Go template.
    59  Valid placeholders for the Go template are listed below:
    60  
    61  | **Placeholder** | **Description**                        |
    62  | --------------- | -------------------------------------- |
    63  | .Container      | ID and name of the container           |
    64  | .ContainerID    | ID of the container                    |
    65  | .ContainerName  | Name of the container                  |
    66  | .Image          | Name of the image                      |
    67  | .Policy         | Auto-update policy of the container    |
    68  | .Unit           | Name of the systemd unit               |
    69  | .Updated        | Update status: true,false,failed       |
    70  
    71  #### **--rollback**
    72  
    73  If restarting a systemd unit after updating the image has failed, rollback to using the previous image and restart the unit another time.  Default is true.
    74  
    75  Note that detecting if a systemd unit has failed is best done by the container sending the READY message via SDNOTIFY.
    76  This way, restarting the unit waits until having received the message or a timeout kicked in.
    77  Without that, restarting the systemd unit may succeed even if the container has failed shortly after.
    78  
    79  For a container to send the READY message via SDNOTIFY it must be created with the `--sdnotify=container` option (see podman-run(1)).
    80  The application running inside the container can then execute `systemd-notify --ready` when ready or use the sdnotify bindings of the specific programming language (e.g., sd_notify(3)).
    81  
    82  @@option tls-verify
    83  
    84  ## EXAMPLES
    85  
    86  Create a Quadlet file configured for auto updates:
    87  ```
    88  $ cat ~/.config/containers/systemd/sleep.container
    89  [Container]
    90  Image=registry.fedoraproject.org/fedora:latest
    91  Exec=sleep infinity
    92  AutoUpdate=registry
    93  ```
    94  
    95  Generate a systemd service from the Quadlet file by reloading the systemd user daemon:
    96  ```
    97  $ systemctl --user daemon-reload
    98  ```
    99  
   100  Start the systemd service and make sure the container is running
   101  ```
   102  $ systemctl --user start sleep.service
   103  $ podman ps
   104  CONTAINER ID  IMAGE                                     COMMAND         CREATED        STATUS        PORTS       NAMES
   105  f8e4759798d4  registry.fedoraproject.org/fedora:latest  sleep infinity  2 seconds ago  Up 2 seconds              systemd-sleep
   106  ```
   107  
   108  Check if a new image is available via `--dry-run`:
   109  ```
   110  $ podman auto-update --dry-run --format "{{.Image}} {{.Updated}}"
   111  registry.fedoraproject.org/fedora:latest   pending
   112  ```
   113  
   114  Update the service:
   115  ```
   116  $ podman auto-update
   117  UNIT           CONTAINER                     IMAGE                                     POLICY      UPDATED
   118  sleep.service  f8e4759798d4 (systemd-sleep)  registry.fedoraproject.org/fedora:latest  registry    true
   119  ```
   120  
   121  ## SEE ALSO
   122  **[podman(1)](podman.1.md)**, **[podman-generate-systemd(1)](podman-generate-systemd.1.md)**, **[podman-run(1)](podman-run.1.md)**, **[podman-systemd.unit(5)](podman-systemd.unit.5.md)**, **sd_notify(3)**, **[systemd.unit(5)](https://www.freedesktop.org/software/systemd/man/systemd.unit.html)**